1) 几个交易赚100万U的故事。
刚刚区块链上发生了一件大事。简单来说就是有两个大怨种在一瞬间失去了百万资金,让我们来看看是怎么回事吧。
#Flashbot #MEV #1M
2) 首先,有三个角色:大怨种-A,套利者-B,黑客-C,不过要注意的是B其实不是一个人,有非常多的套利者在这一段时间都套利成功了。但是有一个大怨种套利者,他就是今天的主角。
3) 首先是大怨种A,他在一笔交易中,卖出了价值150万U的cUSDC,不过,是在uniswapv2上面。值得注意的是CUSDC基本没有流动性,也就是说,这150万U的cUSDC只卖出了大概520U——默哀。
交易地址txid:etherscan.io/tx/0x96a129768…
4)第二个是今天的主角 套利者B,其实他也是大怨种之一,因为他的开心只持续了不到10分钟。他成功的从uniswapv2中买到了大量的低价cUSDC。大概10wu。
txid:etherscan.io/tx/0xf7e44a884… Image
5) 补充一下,还有一笔,这才是大头
etherscan.io/tx/0x2a615005a…
大概120wu,至于为啥要分两笔,我也不知道。 Image
6)好戏要开场了!大概30分钟左右,攻击者C直接将套利者B的套利合约中的WETH直接清空了!
直接拿走1,101.6 ETH ($1,461,515.32)
而有趣的是,攻击者C的攻击合约是在一天前部署的。我估计是打算等B的合约里面有更多钱的时候再开始偷,没想到好事来的那么突然。
etherscan.io/tx/0x631d206d4… Image
7)现在套利者B蚌埠住了,给攻击者C发了个留言,要C拿走20%,然后还钱。
兄弟们,你们觉得会不会还?
etherscan.io/tx/0x6352ab361… Image
8) 大致研究了一下攻击链路,非常简答,黑客构造了一段的代码,然后调用DyDx的SoloMargin合约中的operate方法。这个方法根据传入的参数,可以去调用别的合约代码。于是黑客就调用了套利者B的合约,在他合约内部完成了approve weth到攻击者C地址,然后把WETh转走。

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Box | 826.eth⛩️ 🦇🔊🪖

Box | 826.eth⛩️ 🦇🔊🪖 Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(