Erc20transfer Hack

Reported loss $15K
Ethereum
Improper Access Control

What happened

On October 22, 2024 a bot drained 14,773.35 USDC (about $14,800) from a wallet that had approved an unverified helper contract on Ethereum (0x43dc865e916914fd93540461fde124484fbf8faa). The contract's erc20TransferFrom function had no access control, so anyone could call it to move tokens from any address that had approved the contract. "Erc20transfer" is the label DeFiHackLabs gave the contract after that function; no project behind it has been identified.

The USDC was swapped for about 5.58 WETH on Uniswap V3 in the same transaction. Etherscan labels the sender "MEV Frontrunner Yoink" and shows about 5.57 ETH of the proceeds paid on to an MEV block builder.

Attacker: 0xfde0d1575ed8e06fbf36256bcdfa1f359281455a Attack contract: 0x6980a47bee930a4584b09ee79ebe46484fbdbdd0 Victim wallet: 0x3dadf003afcc96d404041d8ae711b94f8c68c6a5 Attack tx: 0x7f2540af4a1f7b0172a46f5539ebf943dd5418422e4faa8150d3ae5337e92172

How it happened

  1. A wallet had given the helper contract a USDC approval.
  2. The attacker's bot called erc20TransferFrom on the helper, naming USDC as the token, the victim as the source and the bot as the recipient.
  3. The helper did not check who was calling, so it used the victim's approval to move 14,773.35 USDC to the bot.
  4. The bot swapped the USDC for about 5.58 WETH on Uniswap V3 and passed about 5.57 ETH to an MEV builder in the same transaction.

Protocol details

Classification Access Control
Protocol Type Token
Implementation language Solidity

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.