Top

Reflexer Finance bug appears to have led to theft of 5.9 ETH in collateral

September 02, 2026, 3:34 AM
A permissions-check vulnerability in the GebProxyActions contract of Reflexer Finance’s GEB stablecoin system appears to have been exploited, resulting in the theft of collateral worth about 5.9436 ETH, according to blockchain security firm SlowMist. SlowMist said the issue arose when the victim directly called the quitSystem function to close a collateral position, or SAFE, instead of going through the required DSProxy. That incorrectly recorded the SAFE’s owner as the GebProxyActions contract, allowing the attacker to bypass the SAFE access-control check and withdraw the collateral to the attacker’s own address.

Leave the first comment

You need to log in to leave a comment.
Log In
Loading