DAppSocial Hack
What happened
dAppSocial's token pool contract (DAppSocialPoolModel) on Ethereum was drained of about $16,000 in USDT and USDC on September 2, 2023. The flaw was in withdrawTokensWithAlt, which let a user withdraw on behalf of a linked "alt" account. The function checked the caller's balance but subtracted the amount from the from account, without guarding against underflow.
By linking a helper contract with an empty balance and withdrawing through it, the attacker underflowed the helper's balance to a huge number. The helper then withdrew the contract's entire USDT and USDC holdings. Decurity spotted the exploit and notified the dAppSocial team.
No recovery has been reported.
How it happened
- The attacker deployed a helper contract, deposited 2 USDT into the pool with
depositTokens, and had the helper calllockTokensnaming the attacker as its alt account with a lock length of 0, which the contract accepted. - The attacker called
withdrawTokensWithAlt(USDT, helper, 1 USDT). The function checked that the attacker (msg.sender) had enough balance but deducted the amount from the helper's balance of zero. With no underflow check, the helper's recorded balance wrapped to an enormous value. - The helper called
withdrawTokensfor the pool's entire USDT balance and passed the tokens to the attacker. - The same sequence was repeated for USDC. The helper contract then self-destructed, for a total gain of about $16K.
Protocol details
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.