YOLO Games Hack

REPORTED LOSS $1.5M
Medium Access Control Exploit blast

What happened

YOLO Games' June 2024 token sale ended after a whitehat exploited an authorization flaw in the Bazaar liquidity pool on Blast. The whitehat withdrew approximately 392 ETH and rYOLO tokens, then returned 353 ETH. YOLO later confirmed that sale participants had been refunded.

Technical Root Cause

exitPool trusted its sender argument without verifying that the caller owned or was authorized to act for that address. This allowed the factory's withdrawal authority to be impersonated.

Case & protocol details

Classification Protocol Logic / Access Control
Protocol Type Gaming
Implementation language Solidity
Official Website yologames.io/
Protocol Twitter/X @YOLO_Blast

How it happened

  1. The whitehat called BazaarVaultBlast.exitPool with the Bazaar factory address supplied as sender.
  2. The contract did not verify authority over that sender and released the pool assets.
  3. The whitehat contacted the team and returned most of the ETH, retaining a reward.
  4. YOLO ended the sale and refunded participants.

Evidence & learning

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.