Reflexer Finance Stablecoin System Hacked for 5.9 ETH
A permissions-check vulnerability in Reflexer Finance's GEB stablecoin system has been exploited, resulting in the theft of approximately 5.9436 ETH in collateral.
According to SlowMist, a blockchain security firm, the issue arose when a user directly called the quitSystem function to close a collateral position, instead of routing the transaction through the required DSProxy.
This misstep incorrectly recorded the SAFE's owner as the GebProxyActions contract, rather than the user's own address. The attacker was able to bypass the SAFE's ownership check and withdraw the collateral to their own address.
Reflexer Finance, known for its RAI stablecoin, has not yet issued a public statement regarding the incident.