JokInTheBox Hack
What happened
On June 11, 2024 (UTC), an attacker drained the JokInTheBox staking contract on Ethereum by unstaking the same position again and again. JokInTheBox is a sandwich-trading and copy-sniping utility whose profits go to JOK stakers. The staking contract's unstake function did not check or update whether a stake had already been withdrawn, so one stake could be paid out repeatedly from other users' deposits.
ChainAegis reported a loss of about 109 billion JOK, which the attacker swapped for about 9.12 ETH, roughly $34,000. JokInTheBox chose not to relaunch. It promised to airdrop each affected user the exact number of tokens they had staked and lost within 24 hours, using supply it had planned to burn, and to buy back and burn 110 billion JOK over time.
Attacker: 0xfcd4acbc55df53fbc4c9d275e3495b490635f113. Attack contract: 0x9d3425d45df30183fda059c586543dcdeb5993e6. Attack tx: 0xe8277ef6ba8611bd12dc5a6e7ca4b984423bc0b3828159f83b466fdcf4fe054f.
How it happened
- The attacker bought JOK and staked it in the JokInTheBox staking contract with a valid lock period.
- Once the lock period had passed, they called
unstakeon their stake index. unstakereturned the staked JOK but never marked the stake as withdrawn, so the same call worked again.- In one transaction the attack contract kept calling
unstakeon the same index, receiving 366.06 million JOK each time, until the contract ran out of JOK. In total it collected about 109 billion JOK that belonged to other stakers. - They sold the JOK on Uniswap for about 9.12 ETH.
Protocol details
Evidence
- report ChainAegis alert: @JokInTheBoxETH was attacked, lost ~$34K (via fxtwitter mirror) x.com
- report JokInTheBoxETH incident compensation post (via fxtwitter mirror) x.com
- transaction Etherscan transaction 0xe8277ef6...fe054f etherscan.io
- analysis DeFiLlama defillama.com
- analysis Jun 2024 - JokInTheBoxETH Unstaking Vulnerability - $34k (Quadriga Initiative) quadrigainitiative.com
- analysis DeFiHackLabs JokInTheBox_exp.sol PoC raw.githubusercontent.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.