Scan to Download Gate App
qrCode
More Download Options
Don't remind me again today

GANA Theft Review: Private Key Leakage + Parameter Tampering, the Full Process of Attacking from Hundreds of U to Tens of Thousands of U

robot
Abstract generation in progress

[Bit推] The GANA project recently experienced a major security incident — the attacker only staked a few hundred USDT, but ended up withdrawing hundreds of thousands of USDT when unstaking.

A certain security expert discovered after a deep dive that the root cause lies in the leak of the Owner private key of the GANA Payment Stake contract. However, the attackers did not simply and rudely transfer the funds; instead, they used some technical maneuvers: first, they bypassed the onlyEOA check in the unstake function with the 7702 deleGate operation (this check was originally to prevent bots), and then quietly changed the Rate and Fee parameters in the contract.

With this set of combo punches, the exchange rate for staking and unstaking has been completely distorted. Essentially, it is through tampering with the core parameters of the smart contract that the withdrawal rules have been changed to a version favorable to the attacker.

This matter proves once again: there can be no negligence in private key management, and contract permission design also requires multiple layers of protection.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 3
  • Repost
  • Share
Comment
0/400
FlashLoanKingvip
· 19h ago
Turning a few hundred U into hundreds of thousands is truly amazing. Once the Private Key is leaked, everything is over.
View OriginalReply0
SoliditySlayervip
· 19h ago
The leak of the Private Key coupled with parameter tampering, this method is quite something... GANA really has suffered a social death this time. --- A few hundred exchanged for hundreds of thousands? This deal is too good to be true, no wonder some people take risks. --- Again with the Owner's Private Key, when will the project party learn their lesson? --- I need to take a closer look at the 7702 tactic, feels like this wave of attack logic is a bit fierce. --- What about the contract audit? How did such a huge loophole pass? --- Staking can yield ten times the profit, GANA is really helping the Hacker do the work. --- Technical crime indicates that the Hacker is indeed skilled, not just a mere script kid. --- Another project got stolen, this circle really needs to learn self-protection. --- From a few hundred to hundreds of thousands, this level of absurdity is comparable to real-life scams.
View OriginalReply0
NFTArchaeologistvip
· 19h ago
Once the Private Key is leaked, it's over. Such a basic mistake is really unbelievable. Changing hundreds for tens of thousands, how idle must one be? This trap with 7702, it seems like I need to brush up on it. It's another issue with the Owner's Private Key. When will the project party learn their lesson? These operational details need to be studied carefully; there's something to it.
View OriginalReply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)