EOSDice Hack
What happened
EOSDice, a popular dice-betting DApp on EOS, was drained of about 4,633 EOS on November 10, 2018 through its random number generator. It was the second random-number attack on EOSDice in a week: on November 4 an attacker had taken about 2,545 EOS by predicting the dice result. After that first attack the team added an extra deferred step and changed the seed, but the new seed included the EOS balances of several outside accounts, and anyone can change those balances by sending them tokens.
SlowMist attributed the attack to the same hacker who had earlier hit EOSDice and FFgame, and summarised the cause as a seed the attacker could control being added to the random algorithm.
How it happened
- After the November 4 attack, EOSDice moved to a multiple-deferring reveal: the bet is settled in a second deferred action, so the reference block used for the seed is not known when the bet is placed.
- The new seed replaced the contract's own balance (
pool_eos) withtotal_eos, the sum of EOS balances held by EOSDice and five other designated accounts (eosio.ram,betdiceadmin,newdexpocket,chintailease,eosbiggame44), mixed withtapos_block_prefix(),tapos_block_num(), the player name, game id andcurrent_time(). - The attacker placed a bet and, on receiving the
eosio.tokentransfer notification, launched their own twice-deferred transaction with the same delay as EOSDice, so it executed in the same context as the reveal. - By that point every seed input except
total_eoswas fixed, so the attacker's contract repeatedly sent 0.0001 EOS (the minimum transfer) to one of the designated accounts, shiftingtotal_eosuntil the computed roll matched the bet. - Repeating this across bets drained about 4,633 EOS from EOSDice.
Protocol details
Evidence
- analysis DeFiLlama defillama.com
- analysis SlowMist Hacked - EOS incidents (page 5: 2018-11-10 EOSDice; page 6: 2018-11-04 EOSDice) hacked.slowmist.io
- analysis A Survey on EOSIO Systems Security: Vulnerability, Attack, and Mitigation (Ningyu He et al., arXiv 2207.09227, July 2022), Section 4.1.4 Attacks A5 and A6 arxiv.org
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.