New gaming token on Blast exploited for $4.6 million – white hat hacker involved

Share This Post

A hacker exploited a bug in a newly launched gaming token on Blast network — Super Sushi Samurai — to steal roughly $4.6 million worth of Ethereum on March 21 — less than a month from its launch.

The exploit resulted in an approximately 99% slippage in the token’s value following an unauthorized token dump. The attacker extracted 1310 ETH from the token’s main liquidity pool by doubling their balance repeatedly and then selling it all, according to the details Certik shared with CryptoSlate.

Super Sushi Samurai was scheduled to launch its web3 game on the same day. The incident may have been conducted by a white hat hacker currently in touch with the Super Sushi Samurai team. However, the details are unclear as of press time.

Duplication bug

Investigations into the incident revealed that an unauthorized party acquired 690 million SSS tokens and subsequently initiated a series of transactions through an attack contract specifically designed for this purpose.

By exploiting a vulnerability within the platform’s _update() function, the attacker was able to duplicate the tokens in their possession 25 times. This manipulation inflated the token quantity to 11.5 trillion, which was eventually exchanged for approximately 1,310 ETH, equivalent to around $4,590,827.

The exploit leveraged a flaw in the smart contract’s balance update mechanism, which failed to accurately reflect the changes when tokens were transferred to the same address. This oversight enabled the exponential increase in the attacker’s token balance without legitimate transactions.

In February, the same bug was used to exploit an Ethereum-based token called MINER. The hack resulted in a loss of 168.8 ETH.

Recovery efforts

Following the breach, Super Sushi Samurai has engaged with its community, providing updates and assurances through its official Telegram channel and other social media platforms.

The team said it is trying to contact the exploiter, and the most recent tweet from the gaming platform indicates a white hat hacker has reached out about the incident. However, it is unclear whether the white hat is responsible for the exploit or helping recover the funds as of press time.

Super Sushi Samurai said:

“We’re working with the white hat on the safe return of funds. An update and post-mortem will follow.”

The address containing the compromised funds has been publicly disclosed in an effort to facilitate the tracking and potential recovery of the lost assets:

“0x786C8f95C17BB990a040dc4D6539B01FC1b72842”

The team’s communication efforts aim to keep stakeholders informed about the incident’s developments and the measures to address the security vulnerability.

This incident highlights the critical importance of robust security protocols in the crypto sector, where the digital nature of assets makes them vulnerable to such exploits. It also highlights platforms’ ongoing challenges in safeguarding against sophisticated cyber threats.

The post New gaming token on Blast exploited for $4.6 million – white hat hacker involved appeared first on CryptoSlate.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

‘Microsoft of Blockchains:’ Bitwise Doubles Down on Ethereum’s Fundamentals

Bitwise, a crypto index fund and ETF provider, believes that ethereum has the fundamentals needed to recover from its bad price performance compared to currencies like bitcoin Bitwise CIO Matt Hougan

Bitcoin Demand Surge: Binance Buyers Take Charge As Coinbase Premium Falls

A recent analysis from a CryptoQuant analyst, known by the pseudonym ‘Avocado Onchain,’  has highlighted a notable development in the Bitcoin market According to the analyst’s observations,

Top 3 Undervalued Solana Meme Coins That Can Rally 500% From Here

Following the success of multiple tokens launched on the blockchain in 2023, Solana meme coins have become a major staple of the crypto investing community With the likes of Dogwifhat, BONK, and

Court Orders New York Man to Pay $36M for Forex, Digital Asset Fraud

William Koo Ichioka has been ordered to pay over $36 million after admitting to a forex and digital asset fraud scheme His scam, which started in 2018, involved falsifying financial documents and

Avalanche (AVAX) Rallies On Fed Rate Cut, DeFi Growth Boosts Long-Term Outlook

With its price climbing 17% over the past seven days, Avalanche (AVAX) has lately been on a winning run Right now, the cryptocurrency is trading at $2812, up 7% over the past 24 hours alone This

US Sentences Nigerian Darknet Fraud Leader to Five Years in Prison for $6M Scheme

A Nigerian national has been sentenced to five years in federal prison for his role in a massive darknet fraud scheme that intended to cause over $6 million in losses, according to the US Department