News
SlowMist: ONTR token contract access control vulnerability resulted in a loss of approximately $98,000.
en
On May 29th, SlowMist monitoring revealed that the ONTR token contract experienced a loss of 49.4801 WETH, valued at approximately $98,000, due to an access control vulnerability in the "onlyOwner" modifier. An attacker (0xe806...b760) exploited this flaw by bypassing permission checks when "owner" was "address(0)". They then called "transferOwnership()" to designate their own contract as the owner. Subsequently, they invoked "desertJasper()" to add a hidden balance to the queue, followed by "glenFlash()" to execute "ashBud()". This action directly inflated the address balance by 1e30 basic units without altering "totalSupply". The attacker then transferred these inflated tokens to PancakePair (0xd46d...83fd) and converted them to WETH via "swap()".