GAME Hack

TOTAL LOST $50K
Low Reentrancy

What happened

GAME experienced a reentrancy attack resulting in a loss of 49,596 USD.

On February 12, 2024, an attacker exploited a reentrancy vulnerability in a GAME's smart contract by repeatedly calling the makeBid() function. The stolen funds were transferred to another EOAs and then the part was deposited into FixedFloat, while the remainder was sent to an unknown address with over 2 million transactions. The attacker obtained 1.1 ETH from an address to which sent some of the stolen funds after the attack.

The attack began approximately 7 hours after the exploited contract was created.

Attacker Address:

https://etherscan.io/address/0x145766A5…675A0B

Address which funded the attacker:

https://etherscan.io/address/0x077D360f…e7C4A4

Malicious Transactions:

https://etherscan.io/tx/0xe07fa7cf…c2e32f

https://etherscan.io/tx/0x1624cd34…68f6c7

https://etherscan.io/tx/0x0eb8f8d1…1bd5c4

Malicious Contracts:

https://etherscan.io/address/0x8d4dE2Bc…74D12a

https://etherscan.io/address/0x327aa670…B66dCd

FixedFloat Deposit Transaction:

https://etherscan.io/tx/0xf19de65b…57464b

Case & protocol details

Classification Other
Protocol Type Exploit/Reentrancy

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.