These past few days, I've helped some people follow up on the strange issues they encountered with $WLFI being "phished" and other odd problems, especially the private key leak that led to addresses being delegated to malicious contracts by 7702. When it's time to claim $WLFI, it's highly likely that these groups will conveniently snatch it away... We don't engage in running away; I only point out what the essence of the problem is. Also, I don't have a single $WLFI, wishing these friends a smooth rescue.
Cos(余弦)😶‍🌫️
Cos(余弦)😶‍🌫️2025年8月31日
經典的 EIP-7702 釣魚利用。首先你朋友私鑰洩露了,釣魚團伙(可能不止一個)給你朋友私鑰對應的錢包地址埋伏好了 EIP-7702 利用機制,這個機制只要你試圖想轉走其中剩餘 token,比如這些被扔進 Lockbox 合約的 $WLFI,你打入的 Gas 都會被“自動”轉走… 搶跑思路是可行的:打入 Gas、把埋伏的 EIP-7702 取消或替換成自己的、轉走價值 token,這三個動作用 flashbots 在一個區塊裡打包發送…但慢霧沒做搶跑業務,如果有需要,試試聯繫 @0xAA_Science @BoxMrChen 他們。 注意:首先是私鑰洩露了。
86.09K