Unibot has recently become the target of a security breach. It is a popular Telegram trading bot for managing cryptocurrency assets. Smart contract audit platform, BlockSec, was the first to the ongoing attack. Unibot team has not been successful in resolving the security issue yet at the the press time. Unibot has officially acknowledged the incident on social media. The announcement acknowledged a token approval vulnerability in the new router and temporarily suspended its use to fix it.
Unibot @TeamUnibot was reported to be hacked.
As the code is not open-sourced, we suspect that there is a lack of input validation of the function 0xb2bd16ab in the 0x126c contract, which allows an arbitrary call. Therefore, an attacker could invoke ‘transferFrom’ to transfer… https://t.co/X1pXEZ9b0h pic.twitter.com/En18bWdzOr
— BlockSec (@BlockSecTeam) October 31, 2023
Unibot Users Urged to Safeguard Funds Amid Ongoing Attacks
The hacker stole $613,000 in assets due to the security failure. Unibot users who have suffered negative consequences should immediately protect their finances and prevent further intrusion.
Unibot users are advised to follow some guidelines. Firstly Unibot requires fast crypto asset transfers to secure wallets or platforms. Secondly, Unibot users should also remove any earlier authorizations for the compromised contract.
The security breach perpetrator transferred 353.2 ETH, worth the stolen cash, to TornadoCash. This incident emphasizes the need to protect assets. Unibot has assured users that they would be reimbursed for any financial losses caused by the router’s security flaw. Additionally, the technology protects users’ keys and money. Moreover, Unibot has pledged to provide a complete response after the event inquiry.
The vulnerability exploited in this incident is called “CAll injection.” This vulnerability allows unauthorized parties to introduce updated harmful calldata into the 0xb2bd16ab() function to alter Unibot contract token transfers.
Unibot Promises Quick Compensation and Enhanced Protections Ufter Security Breach
In an official statement from Unibot’s Twitter account, the company acknowledged the breach and provided the following message to its users:

This incident highlights the challenges cryptocurrency platforms face and the importance of strong security protocols to protect digital assets. Unibot is committed to quickly resolving issues and protecting user funds. Users should immediately transfer their cryptocurrency to secure wallets and delete any hacked contract authorizations to reduce risks. Unibot will compensate victims and secure their funds and keys. The incident shows that crypto security is still a problem, emphasizing the need for solid security protocols.

