TronCrush Hack
What happened
TronCrush was a TRON DApp whose TRC20 token TCC paid bonus distributions. On March 29, 2019, the first bonus distribution day, the exchange TronTrade suspended TCC transfers and the TronCrush team said the TCC contract had bugs.
SlowMist records the loss as 150,000 TCC. The cause: the token's transfer never checked that the sender and recipient were different addresses, so sending tokens to yourself created new TCC. No USD value for the loss has been published.
On April 9, 2019, PeckShield published a bug class it called TransferMint, found in more than 20 TRC20 contracts. Two TronCrush contracts were on its list.
How it happened
- PeckShield describes the TransferMint pattern like this: the
transferlogic reads the sender's and recipient's balances first, computes the new values, and then writes both back to storage. - The attacker called
transferwith the same address as sender and recipient. - The write of the recipient's balance overwrote the sender's reduced balance, so the account ended up with its old balance plus the amount sent.
- According to SlowMist, the flaw could create more than 150,000 TCC with nothing behind them. TronTrade then halted TCC transfers.
Protocol details
Evidence
- analysis DeFiLlama defillama.com
- analysis SlowMist Hacked - Tron events (TronCrush entry) hacked.slowmist.io
- analysis Fatal TransferMint Bug in Multiple TRC20 Smart Contracts (PeckShield, 2019-04-09; Wayback copy) web.archive.org
- analysis DAPP trend list: all vulnerability wave fields on EOS may be reproduced (Blocking.net; Wayback copy) web.archive.org
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.