Enjin vulnerability exploited: Attackers extracted ENJ items from about 52 wallets, resulting in a loss of approximately $142,000
chaincatcherEnjin's ERC-1155 "Crypto Items" allows each item to route transfers through a dedicated item adapter. Attackers register and use malicious transfer adapters to bypass owner approval checks, allowing their vulnerable contracts to extract ENJ-supported items from about 52 unrelated holder wallets without approval via transferFrom.Subsequently, the attackers call melt() on each stolen item, redeeming 500 ENJ for each item from the platform's reserves.
This content is for informational and educational purposes only and does not constitute investment advice related to BTCC. BTCC makes every effort but cannot guarantee the truthfulness, accuracy, or originality of the content above.