Menu
Browse

Cyber Incident Victim: EOSBet

Date:

Sep 2018

Location:

China

Summary

A hacker exploited vulnerabilities in the EOSBet gambling platform's smart contracts, specifically a faulty assertion statement, to steal approximately 40,000 EOS (valued at $200,000) from its operating funds. The incident prompted the platform to temporarily suspend operations for forensic analysis, with developers acknowledging the code flaw and noting similar attacks targeting other games using the same exploit. Concurrently, scammers impersonated the platform's official account to send fraudulent messages urging users to transfer funds under false pretenses of reimbursement or compensation, exacerbating the disruption. This breach occurred shortly after the platform had publicly asserted its security and legitimacy following a separate high-value payout to a gambler.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actor Type Location
1 actor Available to members Available to members

Description

On September 14, 2018, the EOSBet gambling decentralized application (dApp) suffered a security breach resulting in the theft of 40,000 EOS tokens valued at approximately $200,000 from its operational wallet. The attack exploited vulnerabilities in the platform's smart contracts, specifically targeting a faulty assertion statement in the code related to an "abi forwarder" function. This vulnerability was not initially recognized as critical by EOSBet developers, who had publicly promoted the platform as exceptionally secure just days prior to the incident. Following the breach, EOSBet representatives confirmed the theft through official communications, acknowledging the severity of the exploit while forensic analysis remained ongoing. The dApp was immediately taken offline to contain the incident and prevent further unauthorized access.

Cyber Incident Image

The breach triggered secondary malicious activity on the EOS blockchain, with scammers impersonating EOSBet's official account ('eosbetdice11') through a similarly named account ('eosbetdicell'). These bad actors sent threatening messages to the attacker's account demanding refunds of "illegal income," while simultaneously attempting to defraud users by promoting fake reimbursement programs tied to BET token exchanges. EOSBet confirmed no such reimbursement initiatives existed at the time. This incident occurred against the backdrop of unusual platform activity earlier that week, when a gambler legitimately won over $600,000 during a 36-hour period – an event EOSBet had vigorously defended as non-exploitative prior to the hack. The platform's developers collaborated with other EOS developers and Block Producers (BPs) to investigate the smart contract vulnerability, which was found to have affected multiple EOS-based gambling applications. No definitive connection was established between the $600,000 payout and the subsequent breach during the initial investigation phase.

Sources
Sources available to members
1 source