Matez Hack
What happened
In November 2024 attackers drained at least $80,000 from Matez (MATEZ) on BNB Chain through an integer truncation bug in its staking contract, MatezStakingProgram. The contract's stake function let a caller be recorded as having staked a huge amount while transferring no MATEZ at all. With that fake stake and a set of fake referral accounts, the attacker claimed MATEZ rewards and sold them.
TenArmor, which raised the alarm, reported many copycat transactions. It said one address, 0x98398781943bc1ff6c63590fce0c7fc679206d0c, took about $70,000 of the total.
How it happened
- The attacker registered in the Matez staking program under an existing sponsor address.
- It called
stake(340282366920938463463374607431768211456), which is exactly 2^128. When that value was narrowed to a smaller integer type, it truncated to 0, so no MATEZ was transferred while the contract recorded a very large stake. - It deployed about 25 helper contracts that each registered under the attacker and staked the same way, meeting the referral requirement for claiming.
- It called
claimto collect MATEZ it had never paid for, sold it, and repeated the cycle. Other addresses copied the attack (example tx0x840b0dc64dbb91e8aba524f67189f639a0bc94ee9256c57d79083bb3fd46ec91).
Protocol details
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.