Unaudited Contract Siphons $40k from DeFi
A recent exploit targeting an unverified smart contract has drained approximately 16.6 WETH, worth around $40,000 at current prices, according to blockchain security firm SlowMist.
The incident highlights ongoing risks in the decentralized finance (DeFi) ecosystem associated with unaudited and unverified code. The affected contract lacked proper access controls and failed to validate target data, allowing an attacker to abuse an existing ERC-20 token approval and bypass owner verification.
This vulnerability is not new; similar exploits have occurred in the past, often targeting contracts that rely on outdated or poorly implemented permission checks.
SlowMist emphasizes the importance of verified contracts, which have published source code that matches their bytecode on-chain. Unverified contracts remain opaque and increase the risk of hidden vulnerabilities.