According to the monitoring of the OKLink security team of OKLink, the DeFi project Thena on BNB Chain was attacked, and the project lost about 20,000 US dollars. According to the analysis of the security team, the main cause of the attack was that the Strategy contract upgrade introduced some configuration problems, and the unstake function Without permission verification, the attacker can unstake the user's pledged assets to the _beneficiary address by calling the unstake function and passing in the parameter _beneficiary. Taking one of the transactions as an example, the attacker calls the unstake function to set _beneficiary as the attack contract, and takes away the user's assets to complete the attack. Attack transaction: https://www.oklink.com/cn/bsc/tx/0xdf6252854362c3e96fd086d9c3a5397c303d265649aee0b023176bb49cf00d4b