Wu reported that Blockaid posted a tweet disclosing that its vulnerability detection system identified a suspected compromise of the administrator key for the MILC Media Metaverse cross-chain bridge on BNB and Ethereum. The historic bridge administrator wallet was used to grant roles to a new attacker EOA, to extract MLT from the bridge contracts, and to transfer administrator control to the attacker’s wallet. Blockaid stated that the compromised administrator withdrew MLT from both bridge contracts and subsequently granted DEFAULT_ADMIN_ROLE and MANAGER_ROLE to the attacker-controlled wallet. The attacker’s EOA is 0x2A09…a38; the affected bridge contracts are 0xCDcC…13e1 on BSC and 0x262f…1974 on Ethereum. To date, approximately 97,003 USDT on BSC and 39.21 ETH routed via Rhinofi on Ethereum have been moved out, totaling roughly $161,000.
https://t.co/QJAQvX1NfH