DAppSocial Hack

Reported loss $16K
Ethereum
Improper Access Control

What happened

dAppSocial's token pool contract (DAppSocialPoolModel) on Ethereum was drained of about $16,000 in USDT and USDC on September 2, 2023. The flaw was in withdrawTokensWithAlt, which let a user withdraw on behalf of a linked "alt" account. The function checked the caller's balance but subtracted the amount from the from account, without guarding against underflow.

By linking a helper contract with an empty balance and withdrawing through it, the attacker underflowed the helper's balance to a huge number. The helper then withdrew the contract's entire USDT and USDC holdings. Decurity spotted the exploit and notified the dAppSocial team.

No recovery has been reported.

How it happened

  1. The attacker deployed a helper contract, deposited 2 USDT into the pool with depositTokens, and had the helper call lockTokens naming the attacker as its alt account with a lock length of 0, which the contract accepted.
  2. The attacker called withdrawTokensWithAlt(USDT, helper, 1 USDT). The function checked that the attacker (msg.sender) had enough balance but deducted the amount from the helper's balance of zero. With no underflow check, the helper's recorded balance wrapped to an enormous value.
  3. The helper called withdrawTokens for the pool's entire USDT balance and passed the tokens to the attacker.
  4. The same sequence was repeated for USDC. The helper contract then self-destructed, for a total gain of about $16K.

Protocol details

Classification Access Control
Protocol Type DeFi Protocol
Implementation language Solidity

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.