Phishing incidents occur frequently, EigenLayer becomes the biggest target of hackers this year?

Re-staking narratives are hot, and EigenLayer is talked about by the community because of this. On March 3, EigenLayer TVL reached 2.931 million ETH, worth approximately US$10.053 billion. EigenLayer's ultra-high TVL also attracted the attention of hackers. On March 5, @CyversAlerts tweeted Indicates that EigenLayer may have fallen victim to phishing.
On March 5, @CyversAlerts monitored that the address starting with 0xae7ab received 4 stETH from EigenLayer, with a contract value of $14,199.57, and was suspected of suffering a phishing attack. At the same time, he pointed out that many victims have signed the "queueWithdrawal" phishing transaction on the main network.

In this regard, well-known chains Detective ZachXBT expressed doubts and commented in a tweet: "Stop spreading fake news because your team cannot read the block explorer." However, EigenLayer users have recently encountered phishing attacks. SlowMist founder Yu Xian also said that EigenLayer’s contract has been exploited by hackers.

Recently, the notorious phishing organization Angel Drainer introduced a new attack mode to attack the "queueWithdrawal" mechanism of the EigenLayer protocol .
Due to the nature of Ethereum staking, transaction approval differs from the regular ERC20 "approval" method. Angel Drainer also aimed at this point and wrote an exploit specifically for the queueWithdrawal (0xf123991e) function of the EigenLayer Strategy Manager contract.
The core of the attack is that the user who signed the "queueWithdrawal" transaction actually approved the malicious "withdrawal" to withdraw the wallet's staking rewards from the EigenLayer protocol to an address chosen by the attacker . Simply put, once you match the transaction on the phishing page, the rewards you staked on EigenLayer will belong to the attacker.
To make detecting malicious attacks more difficult, attackers use the "CREATE2" mechanism to approve these withdrawals to empty addresses. Since this is a new approval method, most security providers or internal security tools do not parse and validate this approval type, so in most cases it is marked as a benign transaction.
Currently, with official permission, calling slashQueuedWithdrawal within 15 days to reduce the existing queued withdrawals can restore lost assets.

In EigenLayer, there is There are two types of re-pledge, namely native ETH re-pledge and LST re-pledge. At the beginning of the entire staking process, EigenLayer needs to create an EigenPod contract for Restaking fund management. When the user withdraws money, the funds will be returned to the EigenPod contract first.
In addition to creating the EigenPod contract, the native Ethereum pledge also needs to run the Beacon chain node service. Since ETH is stored in the Beacon chain, during the withdrawal process In addition to user initiation, the node service provider also needs to help users withdraw relevant funds from the Beacon chain, that is, the withdrawal process requires the consent of both parties.
But for LST re-staking, the funds are directly deposited in EigenLayer's EigenPod contract. This means that users who re-stake LST may suffer losses due to EigenLayer contract risks. This is exactly what this phishing attack is targeting.
Related reading: "Risks and best operating practices of EigenLayer re-pledge》
EigenLayer raised US$64.5 million in two financing rounds, led by Blockchain Capital, Polychain Capital and Ethereal Ventures, Hack VC, Finality Capital Partner, Coinbase Ventures and IOSG Venture participated in the investment.
Related reading: "a16z: Why we invest in EigenLayer》
In addition, EigenLayer TVL continues to increase its holdings. According to Defilamma data, as of this writing At the time of writing, TVL reached US$10.4 billion.

It is this over 100 The $100 million TVL has attracted phishing organizations. Faced with phishing risks and community concerns, SlowMist founder Yu Xian said that whether you open a phishing URL or even connect to a phishing website, the wallet private key will not be stolen.

Risk and reward go hand in hand. The strong financing background and 10 billion TVL not only bring opportunities to users, but also to hackers. At present, the security risks of re-pledge are also known to more people. BlockBeats reminds readers to pay attention to screening when participating in re-pledge projects to avoid losses.
Recommended
The Wall Street Journal: How is AI Trading Stealing the Limelight from Cryptocurrency?
Aug 15, 14:00
Tencent Still Has a Dream
Aug 15, 11:27
To Catch North Korean Hackers, They Set Up a Fake Project
Aug 15, 10:00
From Litigation to Settlement: Positive Signal Released by HTX's Negotiation with FCA
Aug 14, 19:32
11,742 Shipping Addresses Exposed Alongside Trezor Orders
Aug 14, 19:01
Founder Interview: FOMO Creator Explains How They Added 30,000 Users in One Day and Became One of the Fastest-Growing Crypto Apps
Aug 14, 18:37