the integrated financial platform Request Finance attack incident report, only one user was affected by this incident. The attacker invaded the Request Finance front-end system on September 10 and injected authorization instructions into a contract that appeared to be similar to it (name, address, part of ABI interface, recent activities). The victim not only transferred funds to the normal contract when making payment, but also authorized the contract to consume USDC unlimitedly. The team has now implemented additional protection mechanisms and monitoring measures.
Disclaimer: This specification is preliminary and is subject to change at any time without notice. MYTOKEN assumes no responsibility for any errors contained herein.
