PlayDapp Hack
What happened
Attackers stole an administrator private key for PlayDapp's PLA token contract after a spoofed-exchange email installed a tampered remote-access tool on the administrator's PC. They reassigned contract permissions, removed legitimate administrators, and minted 200 million PLA on February 9, followed by 1.59 billion PLA on February 12.
The signing environment for a privileged contract administrator was compromised through a phishing attachment and remote-access malware. Because the stolen key could modify authorization state and authorize minting, compromise of that off-chain key became unrestricted on-chain mint authority.
How it happened
The attacker did not defeat token accounting or a DeFi invariant. A stolen privileged key could change ownership and mint permissions, so the attacker assigned authority to controlled accounts and used the contract's intended mint function to create PLA. Exchange suspensions limited circulation of much of the second mint.
Protocol details
Evidence
- report @playdapp_io incident report twitter.com
- report PlayDapp Post-Mortem on the Hacking Incident playdapp.medium.com
- analysis Web Archive archive.is
- analysis DeFiLlama defillama.com
- analysis Crypto gaming platform PlayDapp loses $290 million worth of tokens in two exploits: Elliptic theblock.co
- analysis PlayDapp Suffers $32.35 Million Security Breach dn.institute
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.