Concentric.fi On Arbitrum Falls Victim To $1.7M Social Engineering Attack
Concentric Fi, operating on the Arbitrum network, has incurred substantial losses exceeding $1.7 million due to a targeted social engineering attack. The breach exploited a vulnerability in the protocol, stemming from unauthorized access gained through a sophisticated attack on one of the team members overseeing the deployer wallet. The compromise of the deployer wallet resulted from a well-executed social engineering attack, ultimately triggering the exploit within the protocol. Despite having audited vaults, the vulnerability arose from the protocol's capacity to undergo upgrades. Leveraging this functionality, the attacker successfully upgraded the vaults, generating new LP tokens, and subsequently depleting the contents of the vaults. https://twitter.com/BeosinAlert/status/1749440827913384156?t=YEZ6c0H220ieuAqQUc9lNA&s=19 The attack involved modifying the implementation contract of the CONE-1 proxy contract. The original ConeCamelotVault contract was replaced with a contract controlled by the attacker. Additionally, the admin of adminMint() was added as the attacker, identified […]