Cointime

Download App
iOS & Android

SharkTeam: Analysis of Atlantis Proposal Attack Principle

On June 10, 2023, Beijing time, Atlantis experienced a proposal attack, resulting in a loss of nearly $1 million. The attackers have made profits of approximately $110,000.

SharkTeam conducted a technical analysis of the incident promptly and summarized security measures. We hope that lessons learned from this event can serve as a reminder for future projects, and together we can build a stronger security defense for the blockchain industry.

1. Incident analysis

Attacker address:

0xeade071ff23bcef312dec938ece29f7da62cf45b

Attack contract:

0x027383C520c289cB5c4B66F8E0c8CA65D0769094

0x613CC544053812aB026d60361212Cdb67B46f42f

0xDc8B8D77d8315de469a806e02f38278E38bDBD0B (fake proposal contract)

Attacked contract:

0x558B96Ee93Ea9C7ec9839BEAfab641d75F94E9a3

Initiate a proposal transaction:

0xac1e694f57db4fdef3275f93b651f62b18d7cb0b3c06977e99b56f2968554afd

Attack transactions:

0xa238ca2d2c57c1678866783b074a0c1204cfaa8c37a383c61a6b8e948d40e3fe

Attack Process:

(1) Firstly, the attacker (0xeade071f) initiated a proposal to the targeted contract (0x558B96Ee) through the attacking contract (0x027383C5). The proposal aimed to modify the admin of the contract.

(2) After a waiting period of 28,800 blocks, which is the voting period for the proposal, the attacker proceeded to vote on the proposal, increasing the forVotes value of the proposal.

(3) The attacker added the proposal to the execution queue of the time lock.

(4) After a waiting period of 172,800 seconds, the proposal was executed, and the admin of the contract was set to the fake proposal contract (0xDc8B8D77).

(5) By invoking the fake proposal contract (0xDc8B8D77), the logic contract of the targeted contract (0x558B96Ee) was set to the attack contract (0x613CC544).

(6) By calling the targeted contract (0x558B96Ee), the attacker actually invoked the backdoor function in the attack contract (0x613CC544) to transfer the authorized user tokens from the targeted contract (0x558B96Ee).

2. Vulnerability Analysis

The governance contract exhibits significant flaws in its logic.

Before adding the proposal to the execution queue of the time lock contract, the verification of the current status of the proposal was not properly conducted.

Due to the bypassing of previous conditions and the fact that eta was initially set to 0 during proposal creation, achieving the Succeeded status of the proposal becomes relatively easy. Once the proposal reaches the Succeeded status, it can be added to the execution queue of the time lock. At this point, it only requires waiting for 172,800 seconds for the current proposal to be executed, completing the attack.

3. Security Recommendations

In light of this attack incident, we should adhere to the following considerations during the development process:

(1) Strictly validate the correctness of the logic when implementing the proposal approval process.

(2) Prior to project deployment, engage a third-party security auditing company to conduct a thorough security audit of the contract logic code.

About us

SharkTeam’s vision is to comprehensively protect the security of the Web3 world. The team is composed of experienced security professionals and senior researchers from all over the world. They are proficient in the underlying theory of blockchain and smart contracts, and provide services including smart contract auditing, on-chain analysis, and emergency response. It has established long-term cooperative relationships with key players in various fields of the blockchain ecosystem, such as Polkadot, Moonbeam, polygon, OKC, Huobi Global, imToken, ChainIDE, etc.
Official website: https://www.sharkteam.org/
Twitter: https://twitter.com/sharkteamorg
Discord: https://discord.gg/jGH9xXCjDZ
Telegram: https://t.me/sharkteamorg

Comments

All Comments

Recommended for you

  • Cointime May 4th News Express

    1. Hong Kong Bitcoin Spot ETF has held 4,218 BTC since its listing three days ago

  • Blockchain Asset Management announces launch of a dedicated blockchain fund for accredited investors

    Blockchain Asset Management, a cryptocurrency fund with a scale of $100 million, announced the launch of an exclusive blockchain fund for qualified investors. The specific amount of funds raised by the fund has not been disclosed yet, but it is said to have reached "eight figures", which means it is in the tens of millions of dollars. In addition, the investment threshold for the new fund is $100,000, and all investors are required to meet the approved standards (annual income exceeding $200,000, net assets exceeding $1 million).

  • Renault's BWT Alpine F1 Team announces partnership with ApeCoinDAO

    The BWT Alpine F1 team under Renault announced a partnership with ApeCoinDAO on X platform, which will introduce APE into the Alpine F1 ecosystem and collaborate with global token holders to launch peripheral products and digital assets inspired by the first ApeCoin. It is reported that according to the cooperation between the two parties, in the future, BAYC NFTs may be able to wear equipment and clothing with the Alpine team logo.

  • BTC breaks through $63,000

    The market shows BTC has broken through $63,000 and is currently trading at $63,014.9, with a daily increase of 6.11%. The market is volatile, so please exercise caution in risk management.

  • The total gas consumption on the Base chain exceeds 10,000 ETH

    According to the blockchain analysis platform Dune Analytics, the total gas consumption on the Base chain has exceeded 10,000 ETH, reaching 10,839.5062 ETH at the time of writing (equivalent to over $33.6 million at current prices). The average gas usage amount is about $0.1754 per transaction (0.000059661 ETH), and the total number of blocks has reached 13.41 million, with an average transaction volume of about 14.63 transactions per block. In addition, the data shows that the total transaction volume on the Base chain has exceeded 196.2 million, with over 8.366 million users and over 184 million user transactions at the time of writing. Furthermore, the total number of contracts created on the Base chain has exceeded 64 million, reaching 64,056,573 in the current period.

  • A wallet received 2,000 ETH from Alemeda/FTX

    As monitored by The Data Nerd, 6 hours ago, wallet 0xaEa received 2,000 ETH (approximately $6.23 million) from Alemeda/FTX. Within a week, it received a total of 8,000 ETH (approximately $24.71 million) from Alameda and deposited 6,000 ETH into Binance.

  • A single transaction with a transaction fee of up to 1.5 BTC appeared on the Bitcoin chain

    According to on-chain data tracking service monitoring , there has been a single transaction on the Bitcoin network with a transaction fee as high as 1.5 BTC, worth about $100,254. It is reported that the sender of the transaction is an address starting with "bc1p4n" and the recipient is an address starting with "bc1pqv".

  • 2 wallets deposited 211 billion SHIB into Coinbase within 10 hours

    According to The Data Nerd's monitoring, within 10 hours, 2 wallets (with the same amount of SHIB) deposited a total of 211 billion SHIB (about 5.16 million US dollars) into Coinbase. These wallets accumulated these SHIBs last week, and if sold at the current price, it would cause a small loss (about 120,000 US dollars).

  • USDT issuance on TON chain reaches $100 million

    According to official data, the issuance and circulation of USDT on the TON chain has reached 100 million US dollars, making TON the fastest-growing blockchain for Tether USDT issuance in Web3 history.

  • USDC circulation decreased by $200 million in the past week, with a total circulation of $33.1 billion

    According to official data, Circle issued a total of 2.8 billion USDC and redeemed approximately 3 billion USDC in the past 7 days, resulting in a decrease in circulation of approximately 200 million USDC. The total circulation of USDC is 33.1 billion US dollars, with a reserve of 33.2 billion US dollars, including approximately 3.4 billion US dollars in cash, and Circle Reserve Fund holding approximately 29.8 billion US dollars.