Stake.com Hack
Incident Overview
Stake.com's hot wallets were exploited on Sep 04, 2023, resulting in the loss of $41,408,903 across Ethereum, Binance Smart Chain, and Polygon networks.
Stake.com, a crypto gambling protocol, reported a compromise of its Ethereum, Polygon, and Binance Smart Chain hot wallets on Sep 04, 2023. The attacker compromised the private keys and drained various tokens, totaling $41,408,903 in losses. Stake.com reassured users that their funds were safe and that all other wallets remained operational.
The attacker accurately distributed the stolen funds across all affected chains, initially transferring assets from Stake.com's hot wallets to their main address, and then distributing them between several EOA addresses. The affected addresses still hold over $13 million worth of various tokens across the three chains.
- Ethereum
Attacker Address:
https://etherscan.io/address/0x3130662a…0bcd3c
Funds Holders as of Sep 07, 2023:
https://etherscan.io/address/0x94f1b9b6…d58e8a
https://etherscan.io/address/0xbda83686…df0c83
https://etherscan.io/address/0xba367350…4ff30e
https://etherscan.io/address/0x7d84d78b…48ab4e
Funds Draining Transactions:
https://etherscan.io/tx/0x98610e0a…fad54e
https://etherscan.io/tx/0x4629b762…7efe7a
- Binance Smart Chain
Attacker Address:
https://bscscan.com/address/0x4464E910…61ec04
Funds Holders as of Sep 07, 2023:
https://bscscan.com/address/0xff29a52a…bf82e5
https://bscscan.com/address/0x0004A76E…28a0be
https://bscscan.com/address/0x95b66568…afb237
https://bscscan.com/address/0xbcedc4f3…1630aa
https://bscscan.com/address/0xe03a1ae4…afbd62
Funds Draining Transactions:
https://bscscan.com/tx/0xcc696992…ce97f0
https://bscscan.com/tx/0x232267ed…f0f37b
https://bscscan.com/tx/0x65ba9579…238e52
- Polygon
Attacker Address:
https://polygonscan.com/address/0xfe3F568d…c6C4E0
Funds Holders as of Sep 07, 2023:
https://polygonscan.com/address/0xa2621363…09685e
https://polygonscan.com/address/0xf835cc6c…a2d3dc
https://polygonscan.com/address/0xa2e89818…7a8032
https://polygonscan.com/address/0x32860a05…397ce2
Funds Draining Transactions:
https://polygonscan.com/tx/0x30dab44e…5f4858
https://polygonscan.com/tx/0x630466d8…a4178a
Incident Report
Protocol Information
Market Context at Time of Hack
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Stake.com, these are the critical security checks that could have prevented this incident (September 2023).
- Verify all logic paths related to Private Key Compromised (Unknown Method) / Other are guarded by proper access controls and input validation - see the Access Control Attacks attack class for patterns
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialRelated Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Sources & References
- 01
-
02
Web Archive https://archive.ph/1rX6p
- 03
Learn to Prevent the Next Stake.com
The Stake.com hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.