BeautyChain Hack

Reported loss Not disclosed
Ethereum
Infinite Mint

What happened

On 22 April 2018 an attacker exploited an integer overflow in the BeautyChain (BEC) ERC-20 token and gave two addresses about 5.8 x 10^58 BEC each (2^255 base units), far more than the entire legitimate supply. PeckShield's monitoring flagged the transfer at 03:28:52 UTC, traced it to the contract's batchTransfer() function and named the flaw batchOverflow (CVE-2018-10299). It also found more than a dozen other ERC-20 contracts with the same bug.

The token contract could not be patched, so exchanges had to contain the damage. OKEx suspended BEC withdrawals and trading and said it would roll back BEC trades. Several exchanges then paused ERC-20 deposits while they checked other tokens. No USD loss figure has been published.

How it happened

  1. batchTransfer(address[] _receivers, uint256 _value) computed amount = cnt * _value, where cnt is the number of receivers, without overflow protection.
  2. The attacker called it with two receivers and _value = 2^255 (0x8000...00). Multiplying by 2 wraps the product to exactly 0.
  3. With amount == 0 the checks that _value > 0 and that the sender's balance covered amount both passed, and the sender's balance dropped by nothing.
  4. The loop then credited the full 2^255 to each of the two receiver addresses, creating counterfeit BEC out of nothing.

Protocol details

Classification Token & Share Accounting
Protocol Type Token
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.