I discovered this about eight hours before the execution and wrote a thread on my profile, which was followed by members of the @ team. I also sent on-chain messages to all vulnerable IDM wallets. Unfortunately, no one managed to revoke their approval. However, I managed to save 3.2kk USD from one user, as the attacker's second propose couldn't yet be executed.
Final/
I shared data with emergency responders, but inactive wallets are hard to reach.
If you know owners/custodians of the wallets above, please alert them.
Fastest mitigation: revoke old BarnBridge approvals now.
Use https://t.co/PIXl84ygd6
Ignore scam replies.
1/ URGENT @Barn_Bridge warning
I found ~$4M+ in live approval exposure.
Old gov proposals #14/#15 may put user approvals at risk.
#14 can execute anytime. #15 in ~34h.
Used Smart Yield? Read below + revoke.
Use https://t.co/PIXl84ygd6
Ignore replies.
17/ Again: do not trust reply links.
Go directly to:
https://t.co/N3xDyoOqan
Connect your wallet on Ethereum and revoke approvals to the spender addresses above.
Do not send funds.
Do not sign transfers.
Do not interact with “support” accounts in replies.