Erc20transfer Hack
What happened
On October 22, 2024 a bot drained 14,773.35 USDC (about $14,800) from a wallet that had approved an unverified helper contract on Ethereum (0x43dc865e916914fd93540461fde124484fbf8faa). The contract's erc20TransferFrom function had no access control, so anyone could call it to move tokens from any address that had approved the contract. "Erc20transfer" is the label DeFiHackLabs gave the contract after that function; no project behind it has been identified.
The USDC was swapped for about 5.58 WETH on Uniswap V3 in the same transaction. Etherscan labels the sender "MEV Frontrunner Yoink" and shows about 5.57 ETH of the proceeds paid on to an MEV block builder.
Attacker: 0xfde0d1575ed8e06fbf36256bcdfa1f359281455a
Attack contract: 0x6980a47bee930a4584b09ee79ebe46484fbdbdd0
Victim wallet: 0x3dadf003afcc96d404041d8ae711b94f8c68c6a5
Attack tx: 0x7f2540af4a1f7b0172a46f5539ebf943dd5418422e4faa8150d3ae5337e92172
How it happened
- A wallet had given the helper contract a USDC approval.
- The attacker's bot called
erc20TransferFromon the helper, naming USDC as the token, the victim as the source and the bot as the recipient. - The helper did not check who was calling, so it used the victim's approval to move 14,773.35 USDC to the bot.
- The bot swapped the USDC for about 5.58 WETH on Uniswap V3 and passed about 5.57 ETH to an MEV builder in the same transaction.
Protocol details
Evidence
- report d23e alert: Vulnerability Detected & Automated PoC (tx 0x7f2540af...) x.com
- transaction Etherscan transaction 0x7f2540af... etherscan.io
- analysis DeFiLlama defillama.com
- analysis DeFiHackLabs Erc20transfer_exp.sol raw.githubusercontent.com
- analysis Case Study: Exploiting Access Control Flaw in Unverified Contract (Verichains) blog.verichains.io
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.