SmartMesh Hack
What happened
On 24 April 2018 an attacker used an integer overflow in the SmartMesh (SMT) ERC-20 contract to create an astronomically large number of counterfeit SMT out of nothing. PeckShield, which named the bug proxyOverflow (CVE-2018-10376), traced it to the transferProxy() function and found the same flaw in several other tokens, including MESH, which was hit earlier the same day.
SmartMesh said it found the problem on the morning of 25 April and asked Huobi, Gate, OKEx, CEX and other exchanges to suspend SMT trading and transfers. By its count the bug produced an astronomically large number of counterfeit SMT, dozens of orders of magnitude above the legitimate supply. The attacker moved 65,300,289 of them to exchanges and about 16,638,887 were sold before trading stopped; the exchanges froze the rest. The SmartMesh Foundation said it would destroy an equivalent amount of its own SMT to cover the losses and keep total supply at 3,141,592,653. No USD loss figure has been published.
How it happened
transferProxy(_from, _to, _value, _feeSmt, _v, _r, _s)lets a relayer move tokens on behalf of a signer and collect a fee. It checked the sender's balance against_feeSmt + _valueusing uncheckeduint256arithmetic.- The attacker signed a call from their own address with
_value = 0x8fff...ffand_feeSmt = 0x7000...01. Their sum wraps around to 0, so the balance check passed even though the attacker held no SMT. - The contract then credited
_valueto the recipient and_feeSmttomsg.sender, creating two huge SMT balances without debiting anything real. - The attacker sent part of the counterfeit SMT to exchanges and sold it until SmartMesh and the exchanges halted SMT deposits, withdrawals and trading.
Protocol details
Evidence
- analysis DeFiLlama defillama.com
- analysis New proxyOverflow Bug in Multiple ERC20 Smart Contracts (CVE-2018-10376) - PeckShield (Wayback copy) web.archive.org
- analysis SmartMesh Announcement on Ethereum Smart Contract Overflow Vulnerability (Wayback copy) web.archive.org
- analysis DeFiHackLabs SmartMesh_exp.sol raw.githubusercontent.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.