CSIDB logo
Incident

EOSBet

Incident posture

Attack window
Sep 2018
Location
China
Status
Historical
CIA posture
Available to members
Updated
2026-07-16 16:15

Linked entities

Victim
EOSBet
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Sep 2018
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A hacker exploited vulnerabilities in the EOSBet gambling platform's smart contracts, specifically a faulty assertion statement, to steal approximately 40,000 EOS (valued at $200,000) from its operating funds. The incident prompted the platform to temporarily suspend operations for forensic analysis, with developers acknowledging the code flaw and noting similar attacks targeting other games using the same exploit. Concurrently, scammers impersonated the platform's official account to send fraudulent messages urging users to transfer funds under false pretenses of reimbursement or compensation, exacerbating the disruption. This breach occurred shortly after the platform had publicly asserted its security and legitimacy following a separate high-value payout to a gambler.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On September 14, 2018, the EOSBet gambling decentralized application (dApp) suffered a security breach resulting in the theft of 40,000 EOS tokens valued at approximately $200,000 from its operational wallet. The attack exploited vulnerabilities in the platform's smart contracts, specifically targeting a faulty assertion statement in the code related to an "abi forwarder" function. This vulnerability was not initially recognized as critical by EOSBet developers, who had publicly promoted the platform as exceptionally secure just days prior to the incident. Following the breach, EOSBet representatives confirmed the theft through official communications, acknowledging the severity of the exploit while forensic analysis remained ongoing. The dApp was immediately taken offline to contain the incident and prevent further unauthorized access.

The breach triggered secondary malicious activity on the EOS blockchain, with scammers impersonating EOSBet's official account ('eosbetdice11') through a similarly named account ('eosbetdicell'). These bad actors sent threatening messages to the attacker's account demanding refunds of "illegal income," while simultaneously attempting to defraud users by promoting fake reimbursement programs tied to BET token exchanges. EOSBet confirmed no such reimbursement initiatives existed at the time. This incident occurred against the backdrop of unusual platform activity earlier that week, when a gambler legitimately won over $600,000 during a 36-hour period – an event EOSBet had vigorously defended as non-exploitative prior to the hack. The platform's developers collaborated with other EOS developers and Block Producers (BPs) to investigate the smart contract vulnerability, which was found to have affected multiple EOS-based gambling applications. No definitive connection was established between the $600,000 payout and the subsequent breach during the initial investigation phase.

Sources

Sources available to members: 1 source.

CSIDB