扫码下载
BTC $77,620.71 +1.32%
ETH $2,334.73 +2.10%
BNB $628.25 +0.83%
XRP $1.40 +0.86%
SOL $85.32 +1.84%
TRX $0.3232 -0.11%
DOGE $0.1103 +11.27%
ADA $0.2528 +2.64%
BCH $454.83 +1.55%
LINK $9.38 +1.53%
HYPE $40.54 +1.76%
AAVE $98.06 +0.50%
SUI $0.9334 +0.90%
XLM $0.1642 +0.87%
ZEC $334.67 -0.09%
BTC $77,620.71 +1.32%
ETH $2,334.73 +2.10%
BNB $628.25 +0.83%
XRP $1.40 +0.86%
SOL $85.32 +1.84%
TRX $0.3232 -0.11%
DOGE $0.1103 +11.27%
ADA $0.2528 +2.64%
BCH $454.83 +1.55%
LINK $9.38 +1.53%
HYPE $40.54 +1.76%
AAVE $98.06 +0.50%
SUI $0.9334 +0.90%
XLM $0.1642 +0.87%
ZEC $334.67 -0.09%

慢雾:EIP-7702 账户漏洞遭利用,1,988.5 枚 QNT 被盗

2026-04-29 12:10:45
收藏

ChainCatcher 消息,据市场消息,攻击者利用一个存在缺陷的 EIP-7702 账户,从 QNT 储备池盗取 1,988.5 枚 QNT(约合 54.93 枚 ETH)。根本原因在于,该储备池管理员 EOA 通过 EIP-7702 将代码委托给 BatchExecutor 合约,而该合约将无权限控制的 BatchCall 合约设为授权调用方。

由于 BatchCall.batch() 函数未设置任何权限校验,任意外部调用者均可调用,最终导致储备池资产被耗尽。

app_icon
ChainCatcher 与创新者共建Web3世界