EOSBet Hack
What happened
Around 03:00 UTC on 14 September 2018 an attacker took 44,427.43 EOS from the bankroll of EOSBet's dice game on EOS. EOSBet put the loss at about 40,000 EOS, roughly $200,000 at the time (some reports valued it at over $240,000).
EOSBet said the bug was a faulty assertion in its code, in an ABI forwarding function that other EOS games also used. The attacker could call EOSBet's transfer handler directly with a fake transaction, so the contract accepted bets that were never paid for. Losing bets cost nothing, and winning bets paid out real EOS. The attacker ran 23 transactions in under five minutes. EOSBet took the game offline, patched the contract and brought it back the same day.
How it happened
- The attacker invoked the EOSBet contract's
transferhandling directly with a fake hash instead of sending real EOS through the token contract. - A faulty assertion in EOSBet's ABI forwarder let this fake transfer through, so the contract registered a dice bet without receiving any EOS.
- Losing bets cost the attacker nothing; winning bets were paid in real EOS from the bankroll.
- Repeating this in 23 transactions over less than five minutes, the attacker withdrew about 44,427 EOS.
Protocol details
Evidence
- analysis DeFiLlama defillama.com
- analysis Hacker exploits EOS smart contract to steal $200K from gambling app thenextweb.com
- analysis Hacker Hoodwinks House, Uses EOS Smart Contract Exploit to Steal More Than $240K from EOSBet Dice livebitcoinnews.com
- analysis EOSBet Gambling application hacked, crooks stole $200,000 worth of EOS securityaffairs.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.