SpankChain, a cryptocurrency project focused on the adult industry, has suffered a breach that saw almost $40,000 in ethereum stolen.
In a blog post published Tuesday, the SpankChain team disclosed the hack, saying 165.38 ETH had been lost at around 18:00 PST on Saturday.
The intrusion, which the post said was made possible by a bug in the network's payment channel smart contract, also caused $4,000 in SpankChain's BOOTY token to be frozen.
"Unfortunately, as we were in the middle of investigating other smart contract bugs, we didn't realize the hack had taken place until 7:00pm PST Sunday, at which point we took Spank.Live offline to prevent any additional funds from being deposited into the payment channels smart contract."
Of the cryptos stolen, $9,300 worth of ETH and BOOTY belonged to users, and the remainder to the project.
SpankChain warned of 2-3 days' delay ahead while its developers patch the issue behind the hack, redeploy a new smart contract and fix the other contract issues that were already being worked on.
The team says, it seems the attack was due to a "Reentrancy" bug, similar to the one that allowed a major hack of The DAO crypto project in 2016.
"The attacker created a malicious contract masquerading as an ERC20 token, where the 'transfer' function called back into the payment channel contract multiple times, draining some ETH each time," the team said, adding that it will undertake an "In-depth investigation of the attack" in the coming days.
SpankChain further conceded it had decided not to pay for a security audit for the payment channel contract due to the costs involved "Taking into account both the perception value and opportunity cost of the time spent reacting to the hack, it would have been worth it," the post says.
The firm concluded by pledging it would improve its security practices, "Making sure to get multiple internal audits for any smart contract code we publish, as well as at least one professional external audit."
SpankChain Loses $40K in Hack Due to Smart Contract Bug
Udgivet den Oct 9, 2018
by Coindesk | Udgivet den Coinage
Coinage
Nævnt i denne artikel
Seneste nyheder
Se alt
First Mover: What's Next for Bitcoin as Wall Street Gets Vaccine Booster
Bitcoin was higher for a second day, staying in a range of between roughly $15,200 and $15,600, as news of progress in developing a coronavirus vaccine appeared to touch off a rally in U.S. stocks.
Market Wrap: Bitcoin Fails to Break $15.9K; Over 50K ETH Staked on Eth 2.0 Contract
Bitcoin gained Wednesday while Ethereum 2.0 staking has been ramping up.
Citibank Analyst Says Bitcoin Could Pass $300K by December 2021
A senior analyst at U.S.-based financial giant Citibank has penned a report drawing on similarities between the 1970s gold market and bitcoin.
Blockchain Bites: Data Unions. Hard Forks. And One Citi Analyst's Case for $300K BTC.
A Citibank managing director thinks bitcoin could hit $318,000.