Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesCopyBotsEarn

Avalanche Friend.Tech Clone Under Attack, Over $3M Drained

DailyCoinDailyCoin2023/10/30 12:06
By:DailyCoin
  • Avalanche’s viral SocialFi platform is under attack again. 
  • Hackers exploited a smart contract bug to drain the protocol of all its funds.
  • Although Stars Arena has recovered the stolen funds, users remain wary and hesitant.

Avalanche’s viral social app , Stars Arena, found itself in a financial freefall as attackers capitalized on a smart contract bug, leaving the platform nearly penniless. The attack marks the second onslaught in three days, with stolen funds soaring past $3 million.

Stars Arena’s Alarming Attack

Stars Arena, Avalanche’s Friend.Tech clone has faced yet another attack from exploiters. On October 7, hackers orchestrated a daring raid, siphoning off a staggering $3 million worth of AVAX tokens, leaving Stars Arena with under $1 in its coffers. Following reports from numerous users, Stars Arena swiftly acknowledged the breach and issued an urgent warning, advising against any further deposits.

There has been a major security breach with the smart contract.

We're actively checking the issue.

DO NOT deposit any funds.

Stay tuned for updates.

— Stars Arena (@starsarenacom) October 7, 2023

Blockchain security firm Peckshield shared that hackers exploited a reentrancy function in Stars Arena’s smart contract, which allowed them to manipulate the ticket/share price and sell it at 274,000 AVAX or around $2.9 million. 

This is the second attack of its kind. Just two days ago, on Thursday, hackers successfully leveraged another vulnerability in the SocialFi app, pocketing $1 million by redeeming zero shares for AVAX payouts.

Our initial analysis on today's @starsarenacom $2.9M hack indicates a reentrancy issue on the Stars Arena: Shares contract at https://t.co/Hg6C8MCPan

The reentrancy is abused to update the weight when the share/ticket is issued so that 1 share can be sold at a much higher price… https://t.co/17CxO3uLbe pic.twitter.com/fouVjevYTs

— PeckShield Inc. (@peckshield) October 7, 2023

At press time, Stars Arena shared that it had successfully secured its resources from the hackers, closing the gap caused by the exploit. However, the implicated smart contract remains locked and will re-open once it goes through necessary audits. 

This tumultuous turn of events left Stars Arena’s devoted community less than pleased.

Stars Arena Community Uneasy

Stars Arena burst onto the scene just over a week ago, igniting a wildfire of excitement among Avalanche’s ardent community. In record time, it amassed a substantial following, with numerous members raking in substantial AVAX rewards through trading fees on the platform.

This frenzied launch was swiftly overshadowed by a string of relentless exploits, setting off alarms among users. The glaring absence of robust auditing practices left many uneasy, with many community members voicing suspicions of an insider job.

On the Flipside

  • The original Friend.Tech platform was also shaken by a flurry of SIM-Swap attacks , with users losing hundreds of thousands of dollars. 
  • As a result of the hype surrounding Stars Arena, Avalanche saw an inflow of over 500,000 transactions on the network and pumped to the $10 mark. 

Why This Matters

Decentralized social platforms are emerging as the latest trend in the crypto space; however, most of them have suffered at the hands of smart contract bugs and exploits, making users feel uneasy about joining the hype. 

Read what Charles Hoskinson said to his critics:
Cardano Founder Hoskinson Claps Back At Claims of Dishonesty

Read about Yuga Labs’ new direction: 
Yuga Labs Prepares For Layoff Round: “We Aren’t Optimized”

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Stake to earn
CEC, QTLX, GDV and other popular new coins are in hot progress!
Stake now!