Avalanche project Stars Arena suffers $2.9M exploit, leaving smart contract with just $0.051

cyptouser9 months agoCryptocurrencies News149

Hackers exploited a vulnerability on Oct 7 and drained $2.9 million worth of Avalanche (AVAX) tokens from the smart contract of Stars Arena, an Avalanche-based social token platform. The vulnerable smart contract was used to secure tokens on the platform.

In a post on X, Star Arena noted that the platform is still under a Distributed Denial of Service (DDoS) attack. In a DDOS attack, bad actors disrupt the regular functioning of a platform by overwhelming it with a flood of traffic.

Star Arena added:

“We are working on a solution to get everyone’s funds recovered and have the Arena move forward.”

Blockchain security firm PeckShield first identified the attack and attributed it to a reentrancy issue. A reentrancy issue refers to a security flaw that allows an external contract or attacker to repeatedly call back into the vulnerable contract’s functions before the previous calls have been completed.

According to PeckShield, the reentrancy issue allowed the attackers to represent chat room access and sell tickets at exorbitant prices reaching as high as $2,740 each.

While the breach did not impact tokens in user wallets, users cannot realize any value by selling tickets they own.

The exploited vulnerability has depleted the value locked in Stars Arena’s smart contract to just $0.051, according to DefiLlama data. The platform has cautioned users against depositing any funds on the platform.

Previous attack

Stars Arena, an iteration of FriendTech, offers tokens for purchase, granting access to individual chat rooms. These tokens typically follow a bonding curve, increasing in price as more users acquire them. Transaction fees on such platforms are relatively high, with FriendTech imposing a 10% fee on each transaction, divided between the app and the platform’s owner.

Stars Arena had previously faced a smaller vulnerability that allowed the unauthorized draining of AVAX coins from its smart contract. However, since the issue was challenging to exploit, few funds were lost before it was rectified.

At the time, Ava Labs CEO Emin Gun Sirer dismissed security concerns as malicious actors spreading “FUD” (fear, uncertainty, and doubt).

The content on this website comes from the Internet. Due to the inconvenience of proofreading the authenticity and accuracy of the copyright or content of some content, it may be temporarily impossible to confirm the authenticity and accuracy of the copyright or content. For copyright issues or other issues caused by this, please Call or email this site. It will be deleted or changed immediately after verification.

related articles

Nvidia’s Q1 results sent its stock soaring 6% but AI tokens barely moved

Nvidia’s Q1 results sent its stock soaring 6% but AI tokens barely moved

55966e89˃The price of artificial intelligence (AI)-related cryptocurrency tokens briefly tumbled des...

SlowMist uncovers crypto scam exploiting altered Ethereum nodes

SlowMist uncovers crypto scam exploiting altered Ethereum nodes

1205f261˃The SlowMist security team has uncovered a novel cryptocurrency scam that exploits altered...

UPbit becomes third major crypto firm to secure licensing in Singapore this October

South Korean top cryptocurrency exchange UPbit’s Singapore subsidiary, UPbit Singapore, has re...

Bitcoin miner Argo Blockchain sells Quebec site for $6.1 million amidst declining BTC production

Bitcoin miner Argo Blockchain sold one of its sites to repay debt amid its declining BTC production...

US lawmakers urge Treasury, IRS to hasten implementation of crypto tax rules by 2 years

U.S. Senators Elizabeth Warren and Angus S. King, Jr. are pressing the U.S. Department of the Treasu...

deBridge launches IaaS solution for cross-chain communication between Ethereum and Solana

Web3 interoperability layer deBridge has launched an Infrastructure as a Service (IaaS) turnkey solu...