Fun

Super Sushi Samurai token plunges 99% due to double-spending glitch

News Feed - 2024-03-22 03:03:53

Zhiyuan Sun5 hours agoSuper Sushi Samurai token plunges 99% due to double-spending glitchOver $4.8 million was withdrawn from its liquidity pool by a self-proclaimed white hat hacker.773 Total views9 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksGameFi project Super Sushi Samurai (SSS), built on Coinbase’s Base layer-2 blockchain and the Telegram messaging app, saw a $4.8 million withdrawal on March 21 from its liquidity pools by a self-proclaimed white hat hacker upon the discovery of a double-spending glitch.


In a statement to Cointelegraph, blockchain analytics firm CertiK noted that “the vulnerability is within the [SSS] contracts _update() function, which doesn’t correctly update balances when transferring to self.” So, when a user transfers their entire balance of SSS tokens to themselves, the resulting balance is doubled.The @SSS_HQ $SSS LP was just drained on blast because their token contract has a bug where transferring your entire balance to yourself doubles it.

The order of operations decrements the balance for "from" and then sets the balance for "to" - if these are the same address, the… pic.twitter.com/RStMcFH3sy— Coffee ☕️ (@coffeexcoin) March 21, 2024


CertiK noted that during the incident, one user, operating the address 0x786C8f95C17BB990a040dc4D6539B01FC1b72842, initially purchased 690 million SSS tokens, transferred the entirety of the balance to themselves, doubled it 25 times, and finally ended “with 11.5 trillion SSS tokens which were then sold for 1,310 ETH (~$4,590,827).”


Shortly after the incident, the user who double-spent the tokens stated in a blockchain message: “Hi team, this is a whitehat rescue hack. Let’s work on reimbursing the users. Please reach out via Blockscan chat from the SSS deployer 0x555b28f3b8b3b8ebd1b06997c2078fd94529f555 on Ethereum mainnet.”


Despite their goodwill, however, it is worth noting that the self-proclaimed white hat led to the collapse of the SSS token after withdrawing $4.8 million in funds. Prior to the collapse, SSS had a total market cap of $27.75 million. The tokens have since lost over 99% of their value. The same day, SSS developers responded: “Hello, white hat; we have reached out to you on Blockscan. Thank you for cooperating with us. SSS Team.”


Just one month prior, the novel ERC-X token Miner crashed by 99% after a user discovered a double-spending glitch that led to the infinite minting of tokens. “It’s a pity that the contract has low-level loopholes. You can double your balance by transferring money to yourself,” said Yu Xian, co-founder of Singaporean blockchain security firm SlowMist, regarding the incident. The glitch led to user losses of over $10 million. 


Related: KyberSwap attacker used ‘infinite money glitch’ to drain funds — DeFi expert# Blockchain# Cryptocurrencies# Security# Hackers# Hacks# DeFiAdd reactionAdd reactionRead moreHacker moves $10M from 2023 phishing incident to Tornado CashTokenized US Treasurys grew to $845M in 2023 — CoinGeckoLayerswap overrides website hack that drained $100K

News Feed

UK AI Safety Institute ventures across the pond with new US location
Savannah Fortis14 hours agoUK AI Safety Institute ventures across the pond with new US locationThe U.K. expands its AI Safety Institute to San Francisco, aiming to leverage Bay Area tech talent and strengthen global AI s
Cardano Price Squeezed Between Support And Resistance – Market Awaits Next Leg
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
RFK Jr: Only Bitcoin can guarantee US dollar’s reserve currency status
Sam Bourgi6 hours agoRFK Jr: Only Bitcoin can guarantee US dollar’s reserve currency statusPresidential candidate Robert F. Kennedy Jr. heard about Bitcoin from his kids. Now, he believes it should be part of the bedro
Blackrock CEO on FTX Collapse: Most Crypto Companies Aren’t Going to Be Around
Blackrock CEO on FTX Collapse: Most Crypto Companies Aren"t Going to Be Around The CEO of Blackrock, the world’s largest asset manager, says that most crypto companies will n
Russia to Decide Between Full Ban and Legalization of Crypto Investments, Trade
Russia to Decide Between Full Ban and Legalization of Crypto Investments, Trade Authorities in Russia are discussing two very different approaches to the regulation of cryptocurren
Former South Korean Social Media Giant to Relaunch Its Business by Creating a New Ethereum-Based Token
Former South Korean Social Media Giant to Relaunch Its Business by Creating a New Ethereum-Based Token A social media giant that significantly impacted South Kor
Video Game Giant Square Enix Plans to Drop a Final Fantasy VII NFT Collection in 2023
Video Game Giant Square Enix Plans to Drop a Final Fantasy VII NFT Collection in 2023 According to the non-fungible token (NFT) company Enjin, the firm has inked a deal with the Ja
Prashant Jha18 minutes agoSam Bankman-Fried just like Bernie Madoff, Cardano founder saysCharles Hoskinson likened SBF to Bernie Madoff, the mastermind behind the largest Ponzi scheme in history, and says the media is gi
‘What If XRP Is The Next Bitcoin?’ Says Dave Portnoy
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
Illegal Use of Cryptocurrency Largely a Myth, Russian Lawmaker Says
Illegal Use of Cryptocurrency Largely a Myth, Russian Lawmaker Says Only a small share of cryptocurrency transactions have illicit purposes and the use of digital coins in illegal
Ana Paula Pereira2 hours agoBinance.US exchange volume slumps amidst crisisOn Sep. 16, exchange volume stood at $5.09 million on Binance.US amidst executive departures and ongoing regulatory scrutiny.686 Total views42 To
DEF buys patent to stop lawsuits against MakerDAO and Compound
Derek Andersen4 hours agoDEF buys patent to stop lawsuits against MakerDAO and CompoundThe patent for “oracle-like” data storage contained technology that was already in existence, DEF said.796 Total views8 Total sha