Nebula Revelation Hack

TOTAL LOST $180K
Low Reentrancy optimism

What happened

Nebula Revelation's staking contract suffered a reentrancy attack, resulting in a loss of 180,264 USD worth 81.3 WETH.

Nebula Revelation, a Web3 space-themed open-world game on Optimism, experienced a reentrancy attack on its staking contract on January 25, 2024. The root cause of the exploit was a lack of reentrancy protection in the withdrawal function of their contracts.Root cause: the withdrawNFL() did not have re-entry protection. The attacker used a self-destructing contract to complete all operations in one transaction, exploiting the security vulnerability.

The stolen funds, amounting to 180,264 USD worth 81.3 WETH, were transferred and bridged to the Ethereum chain.

Attacker Address:

https://optimism.etherscan.io/address/0x1fd0a6a5…c4ef12

Malicious Transaction:

https://optimism.etherscan.io/tx/0xf4fc3b63…5b2328

Malicious Contract Address:

https://optimism.etherscan.io/address/0xE4D41BDD…91087b

Self Destruct Contract Address:

https://optimism.etherscan.io/address/0xfc3b0855…9bBa4C

Hop Protocol, Bridged Transaction:

https://optimism.etherscan.io/tx/0x48beb06d…6e99cb

Case & protocol details

Classification Gaming / Metaverse / Gaming / Metaverse / Gaming / Metaverse / Gaming / Metaverse / Gaming / Metaverse / Gaming / Metaverse / Gaming / Metaverse / Gaming / Metaverse / Gaming / Metaverse / Gaming / Metaverse / Gaming / Metaverse / Gaming / Metaverse / Gam
Protocol Type Exploit/Reentrancy
Affected asset / contract NBL
Smart Contract Language Solidity
Official Website nebularevelation.com/
Protocol Twitter/X @NBLGAME

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.