Hackers Steal $200,000 Worth of EOS, dApp Had Smart Contract Flaw

2018-9-15 09:55

A gambling application that is based on the EOS blockchain has had a flaw in its smart contract system exploited. Hackers were able to make off with $200,000 worth of EOS due to the vulnerability.

EOSBet Taken Offline Following Security Breach

Those behind today’s attack exploited a weakness in one of the EOSBet platform’s smart contracts. Following the incident, the service was taken offline whilst developers tried to pinpoint exactly how such an attack was possible.

According to a report by TheNextWeb, an EOSBet spokesperson has stated:

“[…] A few hours ago, we were attacked, and about 40,000 EOS was taken from our bankroll… This bug was not minor as was stated previously, and we are still doing forensics and piecing together what happened.”

They added that the service should resume full functionality “relatively quickly” and that the incident was caused by a fault within the coding of one of their games. In addition, it appears that the hackers were able to target numerous games with the same code.

It seems that those behind the attack were able to trick the EOSBet’s transfer funds function by using a fake hash. The discovery was first made public by a member of the EOSBet Reddit community. The post by user “thbourlove” showed the code used to exploit the vulnerability. This was responded to by the platform’s official Reddit account:

“Yep, we were hacked. But we also have this exact assertion that you do. I would be careful, it’s a bit deeper than you think.”

It seems that those responsible for the attack have attempted to make the transfers off the platform to the attacker’s wallet appear legitimate by creating an account that looks very similar to that of the official EOSBet wallet. They received small transactions from a number of accounts accompanied by the following message and other similar ones:

“Memo: Please refund the illegal income eos, otherwise we will hire a team of lawyers in China to pursue all criminal liability and losses to you. Eosbet official eos account: eosbetdicell.”

Taking a leaf out of the Twitter-bot scammers’ playbook of spreading ill gotten gains thinly across many wallets, the fake account then sent out many small amounts of EOS tokens to several accounts with this message:

“Memo: Dear players: In order to make up for the loss of eosbet players in the hacking incident, the platform launched a recharge to send BET. 1EOS=1BET, the official eos account: eosbetdicell, the transfer will automatically give the same BET.”

Presumably, the hope is that the disbursement is meant to resemble an official refund for players impacted by the breach.

Although the figures involved are much smaller, the incident is all too reminiscent of the DAO hack on the Ethereum network. There, a smart contract vulnerability was exploited allowing attackers to make off with millions of dollars of investors ETH tokens. It was the response the this that caused the fork that created Ethereum Classic. Clearly, far greater care needs be taken by developers hoping to use smart contracts in their dApps.

The post Hackers Steal $200,000 Worth of EOS, dApp Had Smart Contract Flaw appeared first on NewsBTC.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

EOS (EOS) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 0.00 %
Cегодня L: $0 - H: $0.9581
Капитализация $0 Rank 99999
Цена в час новости $ 5.4242 (-100%)

smart eos had contract hackers worth 200

smart eos → Результатов: 31


Фото:

Blockchain Live: London On September 26th 2018

On September 26th at London Olympia, Europe’s premier event in the blockchain calendar celebrates the latest and greatest in Blockchain, DLT and Smart Contracts. Working with respected affiliates such as the Blockchain Research Institute, techUK and 11:FS, Blockchain Live boasts the big names in blockchain with the likes of Bitfury, ConsenSys and EOS sharing the […] The post Blockchain Live: London On September 26th 2018 appeared first on .

2018-7-27 00:17


Block.One Releases EOSIO Version 1.1.0 Targeted at Scalability, EOS Price up Nearly 3 Percent

Enterprise blockchain, smart contract, and Dapp platform EOS has upgraded its EOSIO open-source blockchain software to version EOSIO 1. 1. 0 to achieve better scalability and performance. The new release, announced July 20, 2018, also focuses on a better usability experience for developers looking to build on the EOS platform “laying a foundation for more scalable application… The post Block.

2018-7-22 01:46


Everything you need to know about EOS Mainnet

Project Overview EOS, created by a genius software programmer, Dan Larimer (Whom also created Steem and Bitshares) is a sound blockchain operating system which aims to provide databases, account permissions, scheduling, authentication, and internet-application communication to improve the efficiency of smart business development and make blockchain scalable to millions of users, facilitating millions of transactions The post Everything you need to know about EOS Mainnet appeared first on ItsBlockchain.

2018-6-16 13:30