White hacker hacked Telegram game Super Sushi Samurai for $4.6 million

Teacher

Professional
Messages
2,677
Reputation
9
Reaction score
629
Points
113
The developers of the Telegram game Super Sushi Samurai reported that exploiting an error in the smart contract allowed the hacker to withdraw $4.6 million from LP wallets.

We have been exploited, it's mint related. We are still looking into the code. Tokens were minted and sold into the LP.
Transaction:https://t.co/F4XeqdyJu2

the exploited funds are in this wallet: https://t.co/NWeTu5vMkj
— Super Sushi Samurai | SSS (@SSS_HQ) March 21, 2024

Yuga Labs developer Coffee claimed that it was a double-spend attack. When the user sent the wallet balance to himself, this doubled the funds.

The @SSS_HQ $SSS LP was just drained on blast because their token contract has a bug where transferring your entire balance to yourself doubles it.

The order of operations decrements the balance for "from" and then sets the balance for "to" — if these are the same address, the… pic.twitter.com/RStMcFH3sy
— Coffee (@coffeexcoin) March 21, 2024

The hacker purchased 690 million SSS tokens and transferred the entire balance to himself 25 times, doubling it. He then sold the 11.5 trillion SSS "mined" in this way for 1,310 ETH (~$4.6 million) on decentralized exchanges.

Later, the hacker contacted the project team through the signature in the transaction and offered to refund the funds. At the time of writing, the parties are in negotiations.

Against the background of the incident, the price of the SSS token collapsed by 99.9% according to CoinGecko.

Telegram-the Super Sushi Samurai game works on the Blast network. Rewards are generated through a combination of a trade tax, a discount on on-chain transaction fees from Blast, and income earned from ether in the LP pool.

Recall that Blast is an EVM-compatible protocol for scaling, which uses Optimistic Rollups. The platform offers a passive income of 4-5% per annum.

The project was launched in November 2023 by the founder of the Blur NFT marketplace under the pseudonym Pacman. Initially, the protocol did not even have a test network and offered users to deposit coins through the bridge.
 
Top