According to Foresight News, CertiK monitoring found a contract vulnerability called MinterProxyV2 on BSC, and users need to revoke the relevant contract permissions. Currently, a total of about $716,000 worth of tokens have been stolen, and the victim's contract has now been suspended. Since the victim's contract did not verify callData, an attack may have occurred. Two attacker wallets have been identified, one of which was funded by FixFloat. Through timing analysis, the attacker initially withdrew funds from TornadoCash and Railgun on December 20.