EOSBet Hack

Reported loss $338K
EOS
Donation Attack

What happened

On 15 October 2018, the EOS gambling dApp EOSBet was drained through a "fake transfer notice" flaw in its dice contract eosbetdice11. The contract acted on any EOS transfer notification it received, without checking that the transfer was actually sent to EOSBet. The attacker moved EOS between two of their own accounts, had one of them forward the notification to EOSBet, and was credited with bets and winnings without paying anything.

PeckShield traced the same trick to five attacker accounts between 10 and 15 October. The largest run, by ilovedice123 on 15 October, collected 138,724 EOS. Within minutes, that account deposited 72,150 EOS to Bitfinex and 65,100 EOS to Poloniex.

PeckShield put the attacker's total at 145,321 EOS, over $700,000 at the time. Early press reports cited 65,000 EOS (about $338,000). EOSBet later published a fix that makes the transfer handler return unless transfer.to == _self.

This was EOSBet's second exploit in about a month, after a fake-EOS attack in September 2018.

How it happened

  1. On EOS, when eosio.token moves EOS from A to B, both accounts get a notification. If B has a contract, it can forward that notification to any other account with require_recipient.
  2. EOSBet's transfer handler ignored transfers sent by itself or eosbetcasino, but it never checked that the transfer's to field was EOSBet itself.
  3. The attacker sent EOS from ilovedice123 to their own account whoiswinner1. The contract on whoiswinner1 forwarded the notification to eosbetdice11 with require_recipient.
  4. EOSBet treated each forwarded notification as a real bet and paid out winnings from its own balance. The attacker's EOS never left their control, so a losing bet cost them nothing.
  5. After small trial runs from other accounts starting on 10 Oct, ilovedice123 ran the large attack on 15 Oct and moved the proceeds to Bitfinex and Poloniex deposit accounts.

Protocol details

Classification Token & Share Accounting
Protocol Type DeFi Protocol
Implementation language C++

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.