EosRoyale Hack
What happened
On 26 October 2018, an attacker drained about 11,000 EOS (about $60,000 at the time) from the team wallet of EosRoyale, a gambling dapp on EOS. The team announced the loss on Reddit and blamed its random number generator. The generator's output could be worked out in advance from information in previous blocks, so the attacker could predict future results and win bets that paid out of the EosRoyale wallet.
The team said it had fixed the flaw and rebuilt its randomization, so that results now come from the hash of a future block at the time of distribution, not from data already on-chain. EOS Royale was attacked again in August 2019 (about 18,000 EOS, method unreported). That is a separate incident.
How it happened
- EosRoyale derived game outcomes from a random number generator seeded with information from previous blocks, which anyone could read on-chain.
- The attacker used that same previous-block data to calculate the numbers the generator would produce next.
- Knowing outcomes in advance, the attacker placed only winning plays and drew about 11,000 EOS (about $60,000) out of the EosRoyale team wallet.
Protocol details
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.