BeautyChain Hack
What happened
On 22 April 2018 an attacker exploited an integer overflow in the BeautyChain (BEC) ERC-20 token and gave two addresses about 5.8 x 10^58 BEC each (2^255 base units), far more than the entire legitimate supply. PeckShield's monitoring flagged the transfer at 03:28:52 UTC, traced it to the contract's batchTransfer() function and named the flaw batchOverflow (CVE-2018-10299). It also found more than a dozen other ERC-20 contracts with the same bug.
The token contract could not be patched, so exchanges had to contain the damage. OKEx suspended BEC withdrawals and trading and said it would roll back BEC trades. Several exchanges then paused ERC-20 deposits while they checked other tokens. No USD loss figure has been published.
How it happened
batchTransfer(address[] _receivers, uint256 _value)computedamount = cnt * _value, wherecntis the number of receivers, without overflow protection.- The attacker called it with two receivers and
_value = 2^255(0x8000...00). Multiplying by 2 wraps the product to exactly 0. - With
amount == 0the checks that_value > 0and that the sender's balance coveredamountboth passed, and the sender's balance dropped by nothing. - The loop then credited the full
2^255to each of the two receiver addresses, creating counterfeit BEC out of nothing.
Protocol details
Evidence
- analysis DeFiLlama defillama.com
- analysis ALERT: New batchOverflow Bug in Multiple ERC20 Smart Contracts (CVE-2018-10299) - PeckShield (Wayback copy) web.archive.org
- analysis Crypto Exchanges Pause Services Over Contract Bugs - CoinDesk coindesk.com
- analysis DeFiHackLabs BEC_exp.sol raw.githubusercontent.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.