Gate Square “Creator Certification Incentive Program” — Recruiting Outstanding Creators!
Join now, share quality content, and compete for over $10,000 in monthly rewards.
How to Apply:
1️⃣ Open the App → Tap [Square] at the bottom → Click your [avatar] in the top right.
2️⃣ Tap [Get Certified], submit your application, and wait for approval.
Apply Now: https://www.gate.com/questionnaire/7159
Token rewards, exclusive Gate merch, and traffic exposure await you!
Details: https://www.gate.com/announcements/article/47889
Fusion optimizer on Arbitrum suffers EIP-7702 permission attack, losing 336,000 USDC
【ChainNews】Arbitrum ecosystem faces issues again. The USDC optimizer Vault launched by Fusion was attacked on January 6, resulting in a loss of $336,000.
The cause of the incident is quite typical—the old version of the Vault code did not properly validate the “fuse” logic, giving hackers an opportunity. Even more seriously, the attacker exploited EIP-7702, manipulating the administrator permissions through this mechanism, injecting malicious logic modules, and ultimately transferring the funds to Tornado.Cash.
From a technical perspective, this incident is actually a combination of two vulnerabilities: one is a logical flaw in the contract itself, and the other is weak permission management due to insufficient understanding of new Ethereum features (EIP-7702). The combination of these factors created a fatal vulnerability.
The good news is that this old Vault was deployed 490 days ago and is rarely used now. Fusion’s official statement says that other vaults are fine, so there’s no need to panic. The official stance is also quite positive, indicating they will use DAO funds to compensate users for their losses. They are currently working with security firms like SEAL, Hexagate, and Blockaid to track the stolen funds. A technical review has also been released; those interested in the details of the vulnerability can check it out.