Paddle: Ankr aBNBc token contract has an infinite minting vulnerability
ChainCatcher news, according to PeckShield analysis, the Ankr aBNBc token contract has an infinite minting vulnerability. Although the mint() function is protected by the onlyMinter modifier, there is another function (with the 0x3b3a5522 func.signature) that can completely bypass caller verification to achieve infinite minting.In addition, the Ankr attacker created a token called Fuck BNB and provided 15 ETH to establish a liquidity pool for it on Uniswap V2. (source link)