EOSBet Hack

Reported loss $200K
EOS
Infinite Mint

What happened

Around 03:00 UTC on 14 September 2018 an attacker took 44,427.43 EOS from the bankroll of EOSBet's dice game on EOS. EOSBet put the loss at about 40,000 EOS, roughly $200,000 at the time (some reports valued it at over $240,000).

EOSBet said the bug was a faulty assertion in its code, in an ABI forwarding function that other EOS games also used. The attacker could call EOSBet's transfer handler directly with a fake transaction, so the contract accepted bets that were never paid for. Losing bets cost nothing, and winning bets paid out real EOS. The attacker ran 23 transactions in under five minutes. EOSBet took the game offline, patched the contract and brought it back the same day.

How it happened

  1. The attacker invoked the EOSBet contract's transfer handling directly with a fake hash instead of sending real EOS through the token contract.
  2. A faulty assertion in EOSBet's ABI forwarder let this fake transfer through, so the contract registered a dice bet without receiving any EOS.
  3. Losing bets cost the attacker nothing; winning bets were paid in real EOS from the bankroll.
  4. Repeating this in 23 transactions over less than five minutes, the attacker withdrew about 44,427 EOS.

Protocol details

Classification Token & Share Accounting
Protocol Type DeFi Protocol
Implementation language C++

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.