Reflexer Finance Exploited: $10,000 in Collateral Stolen via Permissions-Check Flaw
A permissions-check vulnerability in Reflexer Finance's GEB stablecoin system has been exploited, resulting in the theft of approximately 5.9436 ETH in collateral.
The incident highlights the risks associated with smart contract interactions and emphasizes the importance of rigorous security audits in decentralized finance (DeFi).
The issue arose when a user directly called the quitSystem function to close a collateral position, instead of routing the transaction through the required DSProxy.
This misstep incorrectly recorded the SAFE's owner as the GebProxyActions contract, allowing the attacker to bypass access controls and withdraw the collateral.