<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=ODOS_Protocol_Audited_Executor_Validation_Vulnerability</id>
	<title>ODOS Protocol Audited Executor Validation Vulnerability - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=ODOS_Protocol_Audited_Executor_Validation_Vulnerability"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=ODOS_Protocol_Audited_Executor_Validation_Vulnerability&amp;action=history"/>
	<updated>2026-09-14T14:10:50Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=ODOS_Protocol_Audited_Executor_Validation_Vulnerability&amp;diff=6621&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study 2 With About|source=https://www.quadrigainitiative.com/casestudy/odosprotocolauditedexecutorvalidationvulnerability.php}} {{Unattributed Sources}}  Odos Protocol Log/HomepageOn January 23, 2025, a vulnerability in Odos Protocol’s OdosLimitOrderRouter contract was exploited, resulting in the theft of around $50,000 on Ethereum and Base. The attacker exploited an arbitrary call vulnerability, where unverified user inp...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=ODOS_Protocol_Audited_Executor_Validation_Vulnerability&amp;diff=6621&amp;oldid=prev"/>
		<updated>2025-03-12T19:53:09Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study 2 With About|source=https://www.quadrigainitiative.com/casestudy/odosprotocolauditedexecutorvalidationvulnerability.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Odosprotocol.jpg&quot; title=&quot;File:Odosprotocol.jpg&quot;&gt;thumb|Odos Protocol Log/Homepage&lt;/a&gt;On January 23, 2025, a vulnerability in Odos Protocol’s OdosLimitOrderRouter contract was exploited, resulting in the theft of around $50,000 on Ethereum and Base. The attacker exploited an arbitrary call vulnerability, where unverified user inp...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study 2 With About|source=https://www.quadrigainitiative.com/casestudy/odosprotocolauditedexecutorvalidationvulnerability.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Odosprotocol.jpg|thumb|Odos Protocol Log/Homepage]]On January 23, 2025, a vulnerability in Odos Protocol’s OdosLimitOrderRouter contract was exploited, resulting in the theft of around $50,000 on Ethereum and Base. The attacker exploited an arbitrary call vulnerability, where unverified user input was combined with a pre-compiled 0x4 Identity contract to bypass the signature validation mechanism and steal tokens. The incident emphasizes the need for thorough security audits, not just for initial versions, but for any new features added to prevent similar vulnerabilities in the future. No user funds were lost. All funds lost were platform profits.&amp;lt;ref name=&amp;quot;odosprotocoltweet-18671&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;odosprotocollinktree-18672&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;odosprotocolhomepage-18673&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;odosprotocolabout-18674&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;odosprotocolquillaudits-18675&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;malicioustransaction-18676&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;halbornodosprotocol-18677&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;verichainsarticle-18678&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About Odos Protocol ==&lt;br /&gt;
Odos Protocol is a decentralized finance (DeFi) platform designed to optimize trading by providing smarter, more efficient solutions. It offers seamless token swaps, flexible strategies like limit orders, and advanced customization options for traders. Odos uses sophisticated routing algorithms to maximize token output by sourcing liquidity from hundreds of sources, minimizing fees, and offering better rates. It supports a wide range of tokens, including blue-chip and niche assets, and simplifies complex processes like market arbitrage and multi-token transactions. Odos also provides powerful APIs for developers to integrate advanced token swaps and liquidity aggregation into their platforms.&lt;br /&gt;
&lt;br /&gt;
Odos Protocol uses a proprietary Smart Order Routing (SOR) algorithm to aggregate decentralized exchanges (DEX) and find optimal routes for cryptocurrency token swaps. As the number of DEXs and liquidity sources grows, Odos efficiently navigates complex, non-linear paths to deliver the best exchange rates across multiple blockchains. Unique to Odos is its multi-token input feature, which allows users to swap multiple tokens in a single transaction. The platform is developed by Semiotic Labs, a team focused on AI, cryptography, and Web3 optimization, with expertise in The Graph protocol and autonomous decision-making technologies.&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
There was insufficient validation of user inputs and inadequate handling of external contract calls, especially with pre-compiled contracts and complex contract functionalities like ERC-6492.&lt;br /&gt;
&lt;br /&gt;
New features added to the Odos Protocol smart contract were not properly audited.&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
On January 23, 2025, a vulnerability in Odos Protocol's Limit Order Contracts was exploited, allowing an attacker to steal approximately $50,000 by bypassing signature checks using a pre-compiled contract.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - ODOS Protocol Audited Executor Validation Vulnerability&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|January 23rd, 2025 9:55:49 AM MST&lt;br /&gt;
|Malicious Base Transaction&lt;br /&gt;
|The malicious transaction occurs on the Base blockchain.&lt;br /&gt;
|-&lt;br /&gt;
|January 23rd, 2025 10:54:00 PM MST&lt;br /&gt;
|Odos Protocol Tweet Update&lt;br /&gt;
|Odos Protocol posts a tweet to inform the community that all user funds are safe following a recent security incident involving their Limit Order contracts. The exploit, which targeted a vulnerability in their audited executor contract, did not compromise any user funds but accessed revenue stored within the contract. The team has resolved the issue by working with auditing partners to update and deploy new contracts and routers. Odos Protocol reassures users that no action is needed from them and emphasizes their commitment to transparency, security, and user protection.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
The attack was made possible by an arbitrary call vulnerability due to insufficient input validation within the contract’s logic. This allowed the attacker to bypass signature verification mechanisms and execute malicious transactions. The attacker deployed a malicious contract and exploited the victim contract to manipulate the system, draining funds from Odos' contracts.&lt;br /&gt;
&lt;br /&gt;
The root cause of the exploit was insufficient validation of user inputs, improper handling of contract functionalities, and an unchecked use of precompile contracts. To prevent such exploits, it was recommended that Odos implement better input validation, enhance signature verification, and introduce reentrancy guards to limit interactions with external contracts. Post-attack, Odos took swift action to address the issue. QuillAudits, a renowned audit firm, emphasized the importance of rigorous security audits to prevent such vulnerabilities and safeguard projects in the Web3 space.&lt;br /&gt;
&lt;br /&gt;
The attack was caused by an arbitrary call vulnerability, where unverified user input was combined with a pre-compiled contract to bypass the signature check. The attacker used the pre-compiled 0x4 Identity contract to bypass the signature check and successfully steal tokens. The exploit occurred because the contract’s signature validation mechanism could be bypassed using this pre-compiled contract, which allowed the attacker to execute malicious transactions without triggering the usual security checks.&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
Losses were estimated by SlowMist at $100,000.&lt;br /&gt;
&lt;br /&gt;
According to QuillAudits, a &amp;quot;series of coordinated attacks resulted in a cumulative loss of approximately $50,000.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
The total amount lost has been estimated at $50,000 USD.&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed?&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
&amp;quot;TL;DR: All user funds are safe. The exploit has been addressed, and no action is needed from users. Your trust and security remain our top priorities.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Today we discovered a malicious attack on our Limit Order contracts. It’s important to highlight that no user funds were compromised during this attack and the exploit has been resolved.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;The attack exploited a vulnerability in our audited executor contract, accessing revenue stored within the contract but not any user funds.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;We’ve worked with our auditing partners to re-verify the updated contracts and deployed them along with new routers to eliminate the exploit.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;We’re deeply grateful for the trust you’ve placed in Odos and remain committed to transparency, security, and user protection.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
There do not appear to have been any funds recovered in this case.&lt;br /&gt;
&lt;br /&gt;
What funds were recovered? What funds were reimbursed for those affected users?&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
What parts of this case are still remaining to be concluded?&lt;br /&gt;
== General Prevention Policies ==&lt;br /&gt;
The incident underscores the importance of validating all user inputs and being cautious with external contract calls, especially when using pre-compiled contracts or handling contract code lengths. The attack highlights the risks of not properly verifying signature checks, especially when using complex contract functionalities like ERC-6492. It is advised that protocols using such features undergo thorough security audits, not only for initial releases but also for any new features added, to avoid introducing similar vulnerabilities.&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;odosprotocoltweet-18671&amp;quot;&amp;gt;[https://twitter.com/odosprotocol/status/1882668362045821146 Odos Protocol - &amp;quot;All user funds are safe. The exploit has been addressed, and no action is needed from users. Your trust and security remain our top priorities.&amp;quot; - Twitter/X] (Accessed Mar 12, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;odosprotocollinktree-18672&amp;quot;&amp;gt;[https://linktr.ee/odosxyz Odos Protocol Linktree] (Accessed Mar 12, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;odosprotocolhomepage-18673&amp;quot;&amp;gt;[https://www.odos.xyz/ Odos Protocol Homepage] (Accessed Mar 12, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;odosprotocolabout-18674&amp;quot;&amp;gt;[https://www.odos.xyz/about Odos Protocol About Section] (Accessed Mar 12, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;odosprotocolquillaudits-18675&amp;quot;&amp;gt;[https://www.quillaudits.com/blog/hack-analysis/odos-protocol-arbitrary-call-vulnerability What Went Wrong With Odos Protocol? - Quill Audits] (Accessed Mar 12, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;malicioustransaction-18676&amp;quot;&amp;gt;[https://app.blocksec.com/explorer/tx/base/0xd10faa5b33ddb501b1dc6430896c966048271f2510ff9ed681dd6d510c5df9f6 The Malicious Base Transaction - Blocksec] (Accessed Mar 12, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;halbornodosprotocol-18677&amp;quot;&amp;gt;[https://www.halborn.com/audits/odos/limit-orders Limit Orders - Odos - Halborn Audit] (Accessed Mar 12, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;verichainsarticle-18678&amp;quot;&amp;gt;[https://blog.verichains.io/p/erc-6492-deployment-vulnerability ERC-6492 Deployment Vulnerability: Leveraging isValidSignature Bypass via Pre-compiled contract - VeriChains] (Accessed Mar 12, 2025)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>