MEV bot loses $180K in ETH from access control exploit
A maximal extractable value (MEV) bot lost about $180,000 in Ether after an attacker exploited a vulnerability in its access control systems. On April 8, blockchain security firm SlowMist reported that the MEV bot lost 1...
A maximal extractable value (MEV) bot lost about $180,000 in Ether after an attacker exploited a vulnerability in its access control systems.
On April 8, blockchain security firm SlowMist reported that the MEV bot lost 116.7 Ether (ETH) because of the lack of access control. Threat researcher Vladimir Sobolev, also known as Officer’s Notes on X, told Cointelegraph that an attacker exploited a vulnerability in the bot, causing it to swap its ETH to a dummy token.
Sobolev said this was done through a malicious pool created by the attacker within the same transaction. The threat researcher added that this could have been prevented if the MEV owner implemented stricter access controls.
Just 25 minutes into the exploit, the MEV’s owner proposed a bounty to the attacker. The owner then deployed a new MEV bot with stricter access control validation.
Sobolev compared the exploit to a similar incident in 2023, where MEV bots lost $25 million after being exploited. On April 23, 2023, bots who performed sandwich trades lost their crypto to a validator that went rogue.
Related: ‘Unlucky’ MEV bot takes out huge $12M loan just to make $20 in profit
Rise in fake MEV bot guidesAn MEV bot on Ethereum is a trading bot that exploits maximal extractable value. This is the maximum profit that can be extracted from block production. This is done by reordering, inserting or censoring transactions within a block.
The bot observes Ethereum’s pool of pending transactions and looks for potential profits. These bots can do front-run, back-run, or sandwich transactions. This makes the bots very controversial as they steal value from regular users during high periods of volatility or congestion.
Despite the controversies surrounding MEV bots, many continue to use them. However, beginners looking to profit from these bots can often fall into a different trap crafted by scammers.
Sobolev told Cointelegraph that there has been a rise in fraudulent MEV bot tutorials online. The researcher said the tutorials offer ways to earn money using MEV bots and publish fake installation instructions. “Very often, this will simply allow hackers to steal your money,” Sobolev said.
He urged users to check their resources and ensure they are not falling prey to scammers.
Magazine: How crypto bots are ruining crypto — including auto memecoin rug pulls
Original source
Read on CointelegraphRelated market context
SpaceX’s IPO exposes the first crack in tokenized stocks – fragmented ownership and allocation
SpaceX priced its IPO at $135 per share on June 11, raised $75 billion in the largest public offering in history, and opened on Na...
Armed Intruders Demand Crypto Access in Fake Food Delivery Home Invasion Case
Armed intruders allegedly used a fake food delivery to get inside a home and demand access to cryptocurrency accounts. The case sh...
Coinbase Council Warns 7 Million Bitcoin May Face Future Quantum Risk
TL;DR Coinbase’s Quantum Advisory Council says post-quantum migration planning should begin before quantum attacks become practica...
Ripple chases AI’s machine economy as XRPL stablecoins near $1 billion
Stablecoin liquidity on the XRP Ledger (XRPL) has nearly doubled over the past month, putting the network within reach of a $1 bil...
Banks are buying Bitcoin vaults, but a quantum problem may be waiting inside
The banks are finally buying the vaults. In May, BNY, the world's largest custodian with $59.4 trillion in assets under custody an...
Tether’s Brief Overtaking of Ether in Value Signals Crypto Market Stress
USDT briefly surpassed Ether in market cap last weekend, signalling investor flight to safety amid Bitcoin's worst week since FTX...