TheRedVillage.com hacked for $80.7K
RootCuase: forwardRequest() is public and makes the router call any registered service with any calldata the caller passes. The router holds the "_authorizeUpgrade" role, so the attacker used it to call upgradeTo on the SeasonService UUPS proxy and point it at their own unverified implementation. That implementation contains a delegatecall backdoor gated to the attacker's tx.origin. SeasonService holds the transferERC20In/Out roles on TRVZooKeeper, the contract players approve WETH to for tournaments.
About 13 minutes later, the backdoor used transferERC20In to pull WETH from ~299 player wallets that had approved ZooKeeper, then used transferERC20Out to send ZooKeeper's whole balance, 31.43 WETH,
Victim: https://polygonscan.com/address/0xc97dcb0492412bfbbf47332f1b1b49e177e8f15c (TRV Router)
@EthSecurity1
Post #424658
370
Forwarded from EthSecurity
