JokInTheBox Hack

Reported loss $34K
Ethereum
Withdrawal Logic Flaw

What happened

On June 11, 2024 (UTC), an attacker drained the JokInTheBox staking contract on Ethereum by unstaking the same position again and again. JokInTheBox is a sandwich-trading and copy-sniping utility whose profits go to JOK stakers. The staking contract's unstake function did not check or update whether a stake had already been withdrawn, so one stake could be paid out repeatedly from other users' deposits.

ChainAegis reported a loss of about 109 billion JOK, which the attacker swapped for about 9.12 ETH, roughly $34,000. JokInTheBox chose not to relaunch. It promised to airdrop each affected user the exact number of tokens they had staked and lost within 24 hours, using supply it had planned to burn, and to buy back and burn 110 billion JOK over time.

Attacker: 0xfcd4acbc55df53fbc4c9d275e3495b490635f113. Attack contract: 0x9d3425d45df30183fda059c586543dcdeb5993e6. Attack tx: 0xe8277ef6ba8611bd12dc5a6e7ca4b984423bc0b3828159f83b466fdcf4fe054f.

How it happened

  1. The attacker bought JOK and staked it in the JokInTheBox staking contract with a valid lock period.
  2. Once the lock period had passed, they called unstake on their stake index.
  3. unstake returned the staked JOK but never marked the stake as withdrawn, so the same call worked again.
  4. In one transaction the attack contract kept calling unstake on the same index, receiving 366.06 million JOK each time, until the contract ran out of JOK. In total it collected about 109 billion JOK that belonged to other stakers.
  5. They sold the JOK on Uniswap for about 9.12 ETH.

Protocol details

Classification Protocol Logic
Protocol Type DeFi Protocol
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.