Matez Hack

Reported loss $80K
BNB Chain
Arithmetic Error

What happened

In November 2024 attackers drained at least $80,000 from Matez (MATEZ) on BNB Chain through an integer truncation bug in its staking contract, MatezStakingProgram. The contract's stake function let a caller be recorded as having staked a huge amount while transferring no MATEZ at all. With that fake stake and a set of fake referral accounts, the attacker claimed MATEZ rewards and sold them.

TenArmor, which raised the alarm, reported many copycat transactions. It said one address, 0x98398781943bc1ff6c63590fce0c7fc679206d0c, took about $70,000 of the total.

How it happened

  1. The attacker registered in the Matez staking program under an existing sponsor address.
  2. It called stake(340282366920938463463374607431768211456), which is exactly 2^128. When that value was narrowed to a smaller integer type, it truncated to 0, so no MATEZ was transferred while the contract recorded a very large stake.
  3. It deployed about 25 helper contracts that each registered under the attacker and staked the same way, meeting the referral requirement for claiming.
  4. It called claim to collect MATEZ it had never paid for, sold it, and repeated the cycle. Other addresses copied the attack (example tx 0x840b0dc64dbb91e8aba524f67189f639a0bc94ee9256c57d79083bb3fd46ec91).

Protocol details

Classification Token & Share Accounting
Protocol Type DeFi Protocol
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.