YOLO Games Hack
What happened
YOLO Games' June 2024 token sale ended after a whitehat exploited an authorization flaw in the Bazaar liquidity pool on Blast. The whitehat withdrew approximately 392 ETH and rYOLO tokens, then returned 353 ETH. YOLO later confirmed that sale participants had been refunded.
exitPool trusted its sender argument without verifying that the caller owned or was authorized to act for that address. This allowed the factory's withdrawal authority to be impersonated.
Case & protocol details
How it happened
- The whitehat called BazaarVaultBlast.exitPool with the Bazaar factory address supplied as sender.
- The contract did not verify authority over that sender and released the pool assets.
- The whitehat contacted the team and returned most of the ETH, retaining a reward.
- YOLO ended the sale and refunded participants.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report x.com
- analysis YOLO Games(Bazaar)事件分析 certik.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.