Nebula Revelation Hack
What happened
Nebula Revelation's staking contract suffered a reentrancy attack, resulting in a loss of 180,264 USD worth 81.3 WETH.
Nebula Revelation, a Web3 space-themed open-world game on Optimism, experienced a reentrancy attack on its staking contract on January 25, 2024. The root cause of the exploit was a lack of reentrancy protection in the withdrawal function of their contracts.Root cause: the withdrawNFL() did not have re-entry protection. The attacker used a self-destructing contract to complete all operations in one transaction, exploiting the security vulnerability.
The stolen funds, amounting to 180,264 USD worth 81.3 WETH, were transferred and bridged to the Ethereum chain.
Attacker Address:
https://optimism.etherscan.io/address/0x1fd0a6a5…c4ef12
Malicious Transaction:
https://optimism.etherscan.io/tx/0xf4fc3b63…5b2328
Malicious Contract Address:
https://optimism.etherscan.io/address/0xE4D41BDD…91087b
Self Destruct Contract Address:
https://optimism.etherscan.io/address/0xfc3b0855…9bBa4C
Hop Protocol, Bridged Transaction:
https://optimism.etherscan.io/tx/0x48beb06d…6e99cb
Case & protocol details
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report twitter.com
- analysis Web Archive archive.ph
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.