Zerogoki Hack
What happened
Zerogoki was attacked by way of compromising the price oracle. The attacker provided a price oracle signed by legitimate private keys, which contained a crafted number of tokens to be swapped. However, the reason why the attacker could construct a valid signature is unknown.
The attacker's address:
https://etherscan.io/address/0xaef46df5…30680d
The transaction behind the attack:
https://etherscan.io/tx/0x81e5f715…21acf8
In the attack transaction, the attacker constructed a message that contained valid signatures and passed a crafted ns parameter (which contains a large number of zUSD). As a result, the attacker used 300 REI to swap 700k zUSD.
Three addresses that are collated with the signatures are:
Case & protocol details
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.