Fun

Crypto game ‘Munchables’ on Blast exploited for $63M

News Feed - 2024-03-27 07:03:09

Tom Mitchelhill1 hour agoCrypto game ‘Munchables’ on Blast exploited for $63MA new NFT game built on the Ethereum Layer-2 Blast has been exploited for nearly 17,500 ETH.847 Total views12 Total sharesListen to article 0:00Breaking newsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksA nonfungible token (NFT) game called Munchables, built on Ethereum layer-2 blockchain Blast, has suffered a $62 million exploit. 


Munchables announced it had been compromised in a March 26 X post at 9:33 pm UTC and said it was tracking the exploiter’s movements and “attempting to stop the transactions.”Source: ZachXBT


Blockchain analyst ZachXBT responded to the post with the wallet address of the alleged attacker, which currently touts a balance of $62.45 million in Ether (ETH), per Blastscan data. 


The wallet address of the exploiter shows that it interacted with the Munchables protocol at 9:26 am UTC, extracting a total of 17,413 ETH, per DeBank dataThe exploiter address with over 17,400 ETH incoming from Munchables. Source: DeBank


The exploiter"s wallet address then transferred $10,700 worth of ETH through the Orbiter Bridge, transferring the Blast ETH back into native ETH. At 10:05 pm UTC, the wallet sent an additional 1 ETH to a fresh wallet address. 


ZachXBT claimed the exploit stemmed from the Munchables team hiring a North Korean developer known by the alias “Werewolves0943.” 


In a March 27 X post, Solidity developer 0xQuit claimed that the Munchables attack had been planned from the outset, with one of the developers upgrading the Lock contract — which is meant to lock tokens in for a specified time — with a new implementation shortly before launch. 


“There were appropriate checks to ensure you couldn’t withdraw more than you deposited. But before upgrading, the attacker was able to assign himself a deposited balance of 1,000,000 Ether,” 0xQuit explained.Source: 0xQuit


“[The] scammer used manual manipulation of storage slots to assign himself an enormous Ether balance before changing the contract implementation to one that appears legit. Then he simply withdrew that balance once TVL was juicy enough,” added 0xQuit. 


Munchables is a Blast-based GameFi app revolving around NFT-based creatures. The Munchables protocol allows players to stake Blast ETH and Blast USD (USDB) to farm Blast points and unlock added in-game perks. 


Related: Blast launches Ethereum L2 mainnet unlocking $2.3B in staked crypto


Several X users including pseudonymous metaverse adviser Cygaar, have called on the Blast team to intervene by forcibly rolling back the chain to before the exploit occurred.


Others pushed back against calls for centralized intervention as it runs against the ethos of decentralized networks — Cinneamhain Ventures partner Adam Cochran argued that it would be “on brand" for Blast to intervene. “It wouldn’t set a good precedent for future exploits/issues, but it is possible."


“An invalid state root would need to be forced by the Blast team which would erase the hacked transaction. The chain might need to halt completely to do this,” added Cygaar.Source: cygaar"While I’m strongly against this action on any other chain, I don’t take Blast as a brand of "serious decentralization chain" but instead as a place for games, experiments, degenry, etc."


“Given that, it doesn’t seem off-brand for them to intervene in defense of user experience. Optimism is ethos alignment, but Blast is gamified social user experience,” Cygaar added.


Magazine: 5 dangers to beware when apeing into Solana memecoins# Blockchain# Cryptocurrencies# Ethereum# Hackers# Games# Scams# Hacks# Blockchain Game# GameFiAdd reactionAdd reactionRead moreGalaxy Digital reports $296M net income in 2023 after $1B loss in 2022Hacker mints 1B tokens in $16M Curio smart contract exploitOsmosis, dYdX and Synthetix most actively developed DeFi projects: Santiment

News Feed

ETH Dencun upgrade attracts more L2 bots and failed txs: Galaxy Research
Martin Young4 hours agoETH Dencun upgrade attracts more L2 bots and failed txs: Galaxy ResearchEthereum’s Dencun upgrade has “greatly improved” the economics of Ethereum rollups. However, Galaxy says it also brough
How to Practice Trading Online Using Tools Provided By Binaryoptions․com
How to Practice Trading Online Using Tools Provided By Binaryoptions․com sponsored Trading online has become very popular over the years. There are no specific requirements for be
SBF’s ‘Truly Trustless’ Protocol — Serum’s Upgrade Authority May Be Tainted, Devs Look to Fork Project
SBF"s "Truly Trustless" Protocol — Serum’s Upgrade Authority May Be Tainted, Devs Look to Fork Project According to Solana’s founder, Anatoly Yakovenko, Serum developers
Avalanche Nears Breakout – Top Analyst Sets $420 Target For AVAX This Cycle
Este artículo también está disponible en español. Avalanche (AVAX) has surged over 40%, reaching a critical supply level that, if broken, could trigger a substantial rall
Arbitrum whales move another $18.5M in tokens after $2.3B unlock
Ezra Reguerra12 hours agoArbitrum whales move another $18.5M in tokens after $2.3B unlock$18.5 million in Arbitrum tokens made their way into Binance after $58 million in ARB were sent to exchanges last week.5747 Total v
South Korean Government to Start Taxing Crypto Trading Profits in 2022
South Korean Government to Start Taxing Crypto Trading Profits in 2022 The South Korean government has issued an amendment to introduce tax on cryptocurrency tra
Iran Will Not Allow Crypto Payments, Prepares to Pilot Digital Rial
Iran Will Not Allow Crypto Payments, Prepares to Pilot Digital Rial Iran will not recognize cryptocurrencies as a means of payment, a high-ranking government official has indicated
Turner Wright2 hours agoInvestors drop class-action lawsuit against Terraform Labs and Do KwonThe dropping of the suit came amid Terra facing a lawsuit brought by the U.S. Securities and Exchange Commission and Do Kwon p
KuCoin says user assets are unaffected by US SDNY indictment
Zhiyuan Sun6 hours agoKuCoin says user assets are unaffected by US SDNY indictmentThe crypto exchange is the seventh largest by 24-hour trading volume.5609 Total views18 Total sharesListen to article 0:00NewsOwn this pie
Grayscale Bitcoin Trust Buys Over 1.5 Times Total BTC Mined Since Halving
Grayscale Bitcoin Trust Buys Over 1.5 Times Total BTC Mined Since HalvingGrayscale Investments has purchased more than 1.5 times the number of bitcoins mined since the third Bitcoin
Samourai Wallet co-founder pleads not guilty, released on $1M bond
Turner Wright2 hours agoSamourai Wallet co-founder pleads not guilty, released on $1M bondThe terms of Keonne Rodriguez’s bail prevent him from engaging in “any cryptocurrency transactions, directly or indirectly,”
Polkadot and Ethereum 2.0 — A Look at the Solutions Building the Scalability of Tomorrow
Polkadot and Ethereum 2.0 — A Look at the Solutions Building the Scalability of Tomorrow Both Ethereum 2.0 and Polkadot are promising sharding-based protocols overcoming the scal