According to Beosin EagleEye monitoring, in response to Wintermute’s $160 million loss in DeFi hacking, the Beosin security team found that attackers frequently used the address 0x0000000fe6a... to call the 0x178979ae function of the 0x00000000ae34... ) transfer, by decompiling the contract, it is found that calling the 0x178979ae function requires permission verification, through function query, confirm that the address 0x0000000fe6a has the setCommonAdmin permission, and the address has normal interaction with the contract before the attack, then it can be confirmed that the private key of 0x0000000fe6a has been Give way. Combined with the address characteristics (0x0000000), it is suspected that the project party used the Profanity tool to generate the address. In the previous article of this tool, security researchers have confirmed that its randomness has security flaws (there is a risk of brute force cracking the private key), which may lead to the possible leakage of the private key. The Beosin security team suggests: 1. The project party removes the setCommonAdmin/owner and other management permissions of the 0x0000000fe6a address and other vanity addresses, and replaces them with safe wallet addresses. 2. Other project parties or users who use the Profanity tool to generate wallet addresses, please transfer assets as soon as possible. Beosin Trace is conducting an analytical trace of the stolen funds.