ToBet Hack
What happened
On December 19, 2018, the EOS dice game ToBet lost 22,403.69 EOS to a rollback attack, one of a wave that also hit BetDice and EOS Max that day. ToBet's off-chain service watched its own node for new bets and sent the reveal (payout) as a separate transaction. The attacker placed bets from an account that block producers had blacklisted, so the bet transactions never made it on-chain.
The reveals still did, and ToBet paid out wins on bets that were never actually placed.
How it happened
- The attacker used an account on the block producers' blacklist to call a proxy contract. The proxy placed a bet with ToBet through an inline action, paying from a second, non-blacklisted account.
- ToBet's own node was a regular full node without the blacklist, so it accepted the bet as a still-reversible transaction.
- ToBet's reveal service polled that node's database, saw the bet, drew a result and sent a separate reveal transaction that paid out if the bet won.
- When both transactions reached block producers, the bet was dropped because its initiator was blacklisted. The reveal came from ToBet's own account, so it was included.
- On-chain, the attacker's account showed only reveal payouts and no bets. Because the bets were never charged, the attacker risked nothing on each attempt.
Protocol details
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.