EOS-Based Token Airdrop Accidentally Gives Away Unlimited Tokens

2018-10-7 00:36

A minor EOS-based token is receiving negative attention after the community discovered a critical error in the code of the token’s ill-fated airdrop.

Se7ens.io recently ran an airdrop that offered a total of 10,000 free tokens to their followers. Unfortunately, the smart contract that executed the airdrop contained several flaws that resulted in an unlimited flow of tokens.

What Went Wrong

The security hole was discovered Thursday by Medium blogger cc32d9, who explained what Se7ens did wrong.

The airdrop utilized a standard smart contract called eosio.token, which is secure and widely used. However, Se7ens.io made several changes that proved to be disastrous.

Notably, the standard “issue” and “transfer” functions were ignored by the smart contract. Se7ens instead relied on a custom “signup” function. As cc32d9 explains:

“[This] takes the desired amount of SEVEN tokens, and just gives the tokens to the user…the tokens appear magically [in] your account.”

The smart contract also neglected to check the number of tokens requested by the user. Because this had been overlooked, cc32d9 managed to request and obtain one billion tokens from the airdrop.

Suggested Reading : Learn more about EOS in our beginner’s guide.

“Bug Bounty”

Cc32d9 did not get to keep his one billion tokens for long. He posted a thread on Reddit that explained the situation, and shortly after, another user reported the bug to Se7ens on Telegram. Se7ens replied with the following message:

“Thank you we will work on fixing that. It’s best to learn about things like that before we get listed. Stay tuned for updates.”

Se7ens’ fix involved taking the tokens back from cc32d9, who was subsequently rewarded with 100,000 tokens as a bug bounty. This action was carried out silently, leaving no record of transactions in the user’s history.

This decision was not well-received by the community. Although cc32d9 did not obtain the tokens fairly, Se7ens’ lack of transparency and readiness to confiscate tokens cast further doubt on the project.

Yet Another Bug

It seems that EOS can’t catch a break: the platform has been host to a number of smart contracts with fatal flaws since its launch in June. Most recently, EOSBet was found to contain a bug that allowed attackers to steal 40,000 EOS tokens.

It’s not clear what exactly is causing EOS’s influx of badly coded smart contracts — nor is it clear whether EOS is in fact worse in this regard than any other blockchain.

In this case, though, much of the blame lies on Se7ens’ developers. As cc32d9 notes, modifications to the standard eosio.token contract are generally unnecessary, and changes certainly should not be made without extensive testing. Se7ens’ modifications were undeniably reckless.

The post EOS-Based Token Airdrop Accidentally Gives Away Unlimited Tokens appeared first on UNHASHED.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

Waves Community Token (WCT) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 1.05 %
Cегодня L: $0 - H: $0
Капитализация $0 Rank 99999
Цена в час новости $ 0.3772 (-100%)

airdrop token eos-based unlimited tokens gives accidentally

airdrop token → Результатов: 26


Фото:

VeChain (VEN) Token Swap on Mobile Wallet Ongoing and a Betting DApp Chooses The Platform

Binance was the first platform to publicly announce that it would be supporting the VeChain (VEN) token swap to VeChain Thor (VET) back in late June. The exchange would then complete the procedure on the 25th of July this year that was accompanied by a 100 Million VTHO Airdrop gift to all the Binance holders […] The post VeChain (VEN) Token Swap on Mobile Wallet Ongoing and a Betting DApp Chooses The Platform appeared first on Ethereum World News.

2018-8-10 13:34


Фото:

It’s Free! NEO and ONT Join Forces for a Second Round of a 40M USD Airdrop!

NEO, one of the main blockchain projects in China, has joined forces with ONT to carry out a significant Airdrop to increase not only the volume but also the number of users of both cryptos. Yesterday, the official NEO blog announced that NEO token holders are going to receive $40 million worth of ONT tokens on […] The post It’s Free! NEO and ONT Join Forces for a Second Round of a 40M USD Airdrop! appeared first on Ethereum World News.

2018-7-13 20:01


2M pass Token Air Trap for Likkey Blockpass Taps Infinito, Hitbtc, gmarkin Listings

In the lead-up to PASS token’s listings on Lykke, HitBTC and Gatecoin exchanges, Blockpass (http://www.blockpass.org) is conducting an airdrop of 2 million PASS tokens, starting 12 July. The airdrop is being implemented through Blockpass’ joint venture partner Infinito Wallet – a versatile, top level multi-currency wallet. Infinito will have an airdrop link on the wallet

2018-7-11 14:36