Nuls Hack

Reported loss $480K
Nuls
Signature Verification Flaw

What happened

On December 22, 2019, an attacker stole 2 million NULS, worth about $480,000, from the NULS team account on the NULS mainnet. NULS said the attacker exploited a flaw in the transaction signature verification logic of NULS 2.2: a specially constructed transaction bypassed the signature check, so nodes accepted a transfer out of the team account without a valid signature.

The attacker sold 548,354 NULS (about $132,000) before the team reacted. NULS contacted exchanges to freeze assets, fixed the verification bug in a new wallet and node release, and hard-forked the chain at block 878000. The fork permanently froze the remaining 1,451,645.65303905 stolen NULS so they could not reach the market. The stolen amount was about 2% of circulating NULS.

How it happened

  1. NULS 2.2 nodes had a flaw in how they verified transaction signatures.
  2. The attacker built a transaction transferring 2 million NULS out of the NULS team account, crafted so it passed through verification without a valid signature from the account's key.
  3. Nodes confirmed the transaction and the 2 million NULS moved to the attacker.
  4. The attacker sold 548,354 NULS before exchanges were asked to freeze deposits.
  5. NULS released patched node software and hard-forked at block height 878000, permanently freezing the 1,451,645.65303905 NULS that had not yet been traded.

Protocol details

Classification Input Validation
Protocol Type Chain
Protocol links Website @nuls

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.