GMBL.COMPUTER Hack
Incident Overview
GMBL Computer, a DeFi Gambling Protocol on Arbitrum, suffered a referral system exploit, resulting in the loss of 768,196 $USD worth 471.33 ETH.
GMBL Computer is a DeFi Gambling Protocol running on the Arbitrum chain. On September 5, 2023, the project's referral system was exploited. The attacker took advantage of a vulnerability that allowed them to place "Ghost" bets on a game, which were registered as losses, and thus enabled the claiming of 5% of these "Ghost" bet losses.
The attacker placed massive "Ghost" bets with one account that was referred by another account, allowing the second account to claim over 8 million $GMBL in referrals before the exploit was stopped. The stolen funds were swapped for ETH and sent to another EOA. Out of the stolen 471.33 ETH, 235.5 ETH was later returned.
Attacker Address:
https://arbiscan.io/address/0x2d6f1b2c…acbd41
Funds Holder as of Sep 15, 2023:
https://arbiscan.io/address/0x2D6F1B2C…acbD41
Malicious Transactions:
https://arbiscan.io/tx/0x339cc90e…ed8608
https://arbiscan.io/tx/0xc8dbe61c…d75e8b
Funds Returning Transaction:
https://arbiscan.io/tx/0xa020be40…c25685
Proposal of Returning Funds:
https://arbiscan.io/tx/0xfb1b2254…bd8ea7
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to GMBL.COMPUTER, these are the critical security checks that could have prevented this incident (September 2023).
- Verify all logic paths related to Referral Claims Logic Exploit / Other are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialFunds Recovery
Recovered
$384K
Net Loss
431135
Sources & References
- 01
-
02
Web Archive https://archive.ph/nI7JM
- 03
Learn to Prevent the Next GMBL.COMPUTER
The GMBL.COMPUTER hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.