y2z Ventures Partner: A phishing attack incident on BSC involving forged authorization to deceive users into paying gas fees
ChainCatcher message, y2z Ventures partner blanker.eth stated on social media that there has been a case of forged authorization on the BSC chain, which then used a security incident to lure users into revoking authorization, resulting in a large gas consumption attack.The attack method is as follows: the attacker deploys a fake ERC-20 contract and then manually forges authorization for a large number of on-chain addresses. When users see security tools prompting them to revoke authorization, they click to revoke and send the transaction, which will mint CHI Tokens into the attacker's wallet, resulting in a loss of approximately $60 worth of BNB.blanker.eth pointed out that BSC can eliminate this type of attack by integrating EIP-3298. (source link)