Time Token Exploit
ID: 2c6bdf5e-7a81-5f4f-a373-1cb0b0e7a8ce
STIX ID: report--2c6bdf5e-7a81-5f4f-a373-1cb0b0e7a8ce
Feed Name: CertiK Blog
Threat Score
On 7 December an attacker exploited a framework-level integration bug between ERC-2771 Forwarder and a contract using multicall/delegatecall to cause the TIME token contract to burn ~99.9% of a targeted pool's TIME supply and extract ~84.6 ETH (~$188K). The root cause is incorrect calldata handling that truncates the verified req.from value, enabling unauthorized execution and subsequent price manipulation and theft; the issue affects other projects using the same pattern.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
