SpankChain Hack

Reported loss $38K
Ethereum
Reentrancy

What happened

On October 7, 2018 (UTC; 6pm Pacific on Saturday, October 6), an attacker drained 165.38 ETH, about $38,000, from SpankChain's payment channel contract on Ethereum using reentrancy. The attack also left about $4,000 of BOOTY tokens stuck in the contract. Of the stolen or stuck funds, 34.99 ETH and 1,271.88 BOOTY (about $9,300) belonged to users; the rest was SpankChain's.

SpankChain noticed the drain about a day later and took Spank.Live offline. It promised to reimburse users in full and to redeploy a patched contract. It said it had skipped a security audit for this contract after receiving quotes of $30,000 to $50,000.

Within days the attacker handed over the private key to an address holding the stolen funds and helped recover the stuck tokens. SpankChain paid a $5,000 bounty, bought the frozen BOOTY back for $4,000, and returned the 5.5 ETH the attacker had used to launch the attack.

Payment channel: 0xf91546835f756da0c10cfa0cda95b15577b84aa7. Attacker: 0xcf267ea3f1ebae3c29fea0a3253f94f3122c2199. Malicious contract: 0xc5918a927c4fb83fe99e30d6f66707f4b396900e. Attack tx: 0x21e9d20b57f6ae60dac23466c8395d47f42dc24628e5a31f224567a2b4effa88.

How it happened

  1. The attacker deployed a malicious contract posing as an ERC20 token, whose transfer function called back into the payment channel contract.
  2. Using that fake token, the contract called createChannel, opening a channel with an ETH deposit and a token balance.
  3. It then called LCOpenTimeout, which lets a user exit a channel the counterparty never joined by refunding the initial ETH and token deposits.
  4. LCOpenTimeout sent the ETH and called the token's transfer before deleting the channel data, so the fake transfer re-entered LCOpenTimeout while the balance was still recorded.
  5. Each loop sent the attacker ETH equal to the channel balance again, until 165.38 ETH had been drained.

Protocol details

Classification Reentrancy
Protocol Type DeFi Protocol
Implementation language Solidity

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.