Beosin: Analysis of the Attack Incident on the Skyward Finance Project
ChainCatcher message, regarding the attack on the Near ecosystem token issuance platform Skyward Finance, according to the Beosin EagleEye security warning and monitoring platform analysis, the attack occurred because the redeem_skyward function of the skyward.near contract did not properly validate the token_account_ids parameter, allowing the attacker 5ebc5ecca14a44175464d0e6a7d3b2a6890229cd5f19cfb29ce8b1651fd58d39 to input the same token_account_id and repeatedly claim WNear rewards.This attack resulted in a loss of approximately 1.08 million Near, about 3.2 million USD. Beosin Trace tracking found that the stolen amount has been transferred by the attacker. Attack transaction