PlayDapp Hack

Reported loss $290.0M
Ethereum
Private-key compromise; privileged mint-authority abuse

What happened

Attackers stole an administrator private key for PlayDapp's PLA token contract after a spoofed-exchange email installed a tampered remote-access tool on the administrator's PC. They reassigned contract permissions, removed legitimate administrators, and minted 200 million PLA on February 9, followed by 1.59 billion PLA on February 12.

Technical root cause

The signing environment for a privileged contract administrator was compromised through a phishing attachment and remote-access malware. Because the stolen key could modify authorization state and authorize minting, compromise of that off-chain key became unrestricted on-chain mint authority.

How it happened

The attacker did not defeat token accounting or a DeFi invariant. A stolen privileged key could change ownership and mint permissions, so the attacker assigned authority to controlled accounts and used the contract's intended mint function to create PLA. Exchange suspensions limited circulation of much of the second mint.

Protocol details

Classification Gaming / Metaverse
Protocol Type Exploit/Access control
Affected asset / contract PLA
Implementation language Solidity
Protocol links Website @playdapp_io

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.