Wednesday, July 3, 2024

New gaming token on Blast exploited for $4.6 million – white hat hacker concerned

A hacker exploited a bug in a newly launched gaming token on Blast community — Tremendous Sushi Samurai — to steal roughly $4.6 million price of Ethereum on March 21 — lower than a month from its launch.

The exploit resulted in an roughly 99% slippage within the token’s worth following an unauthorized token dump. The attacker extracted 1310 ETH from the token’s principal liquidity pool by doubling their stability repeatedly after which promoting all of it, based on the small print Certik shared with CryptoSlate.

Tremendous Sushi Samurai was scheduled to launch its web3 recreation on the identical day. The incident could have been carried out by a white hat hacker at present in contact with the Tremendous Sushi Samurai workforce. Nonetheless, the small print are unclear as of press time.

Duplication bug

Investigations into the incident revealed that an unauthorized celebration acquired 690 million SSS tokens and subsequently initiated a collection of transactions by means of an assault contract particularly designed for this goal.

By exploiting a vulnerability inside the platform’s _update() operate, the attacker was in a position to duplicate the tokens of their possession 25 instances. This manipulation inflated the token amount to 11.5 trillion, which was finally exchanged for roughly 1,310 ETH, equal to round $4,590,827.

The exploit leveraged a flaw within the sensible contract’s stability replace mechanism, which didn’t precisely replicate the adjustments when tokens have been transferred to the identical deal with. This oversight enabled the exponential improve within the attacker’s token stability with out official transactions.

In February, the identical bug was used to use an Ethereum-based token known as MINER. The hack resulted in a lack of 168.8 ETH.

Restoration efforts

Following the breach, Tremendous Sushi Samurai has engaged with its neighborhood, offering updates and assurances by means of its official Telegram channel and different social media platforms.

The workforce mentioned it’s attempting to contact the exploiter, and the newest tweet from the gaming platform signifies a white hat hacker has reached out concerning the incident. Nonetheless, it’s unclear whether or not the white hat is answerable for the exploit or serving to get well the funds as of press time.

Tremendous Sushi Samurai mentioned:

“We’re working with the white hat on the secure return of funds. An replace and autopsy will observe.”

The deal with containing the compromised funds has been publicly disclosed in an effort to facilitate the monitoring and potential restoration of the misplaced property:

“0x786C8f95C17BB990a040dc4D6539B01FC1b72842”

The workforce’s communication efforts purpose to maintain stakeholders knowledgeable concerning the incident’s developments and the measures to handle the safety vulnerability.

This incident highlights the vital significance of sturdy safety protocols within the crypto sector, the place the digital nature of property makes them weak to such exploits. It additionally highlights platforms’ ongoing challenges in safeguarding towards refined cyber threats.



Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles