Slow Fog Cosine: If you have not received the Monad Airdrop, it is recommended to check the Airdrop receiving Address, as there may be a session hijacking vulnerability attack.
According to Mars Finance news, Slow Mist's Yuxian disclosed that some users may not have received the Monad Airdrop and suggested checking whether the wallet address bound on the airdrop claim page claim.monad.xyz is the expected address. Yuxian stated that if the bound address is not what the user expected, they may have encountered a problem similar to that of user Onefly (@Onefly) — the wallet address being bound to a Hacker address, resulting in the official distribution of the airdrop to the Hacker. Yuxian revealed that a white hat hacker had previously synchronized a related vulnerability with him, which has a prerequisite: if someone hijacks the user's session on the Monad airdrop claim page, they can change the receiving wallet address without further confirmation.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
Slow Fog Cosine: If you have not received the Monad Airdrop, it is recommended to check the Airdrop receiving Address, as there may be a session hijacking vulnerability attack.
According to Mars Finance news, Slow Mist's Yuxian disclosed that some users may not have received the Monad Airdrop and suggested checking whether the wallet address bound on the airdrop claim page claim.monad.xyz is the expected address. Yuxian stated that if the bound address is not what the user expected, they may have encountered a problem similar to that of user Onefly (@Onefly) — the wallet address being bound to a Hacker address, resulting in the official distribution of the airdrop to the Hacker. Yuxian revealed that a white hat hacker had previously synchronized a related vulnerability with him, which has a prerequisite: if someone hijacks the user's session on the Monad airdrop claim page, they can change the receiving wallet address without further confirmation.