Dream Health Chain loses $71.800 due to logic error in smart contract
Dream Health Chain was hacked for approximately $71.800 due to a logic error in a smart contract. An attacker was able to receive the same reward multiple times through a flaw in the system that governs reward distribution.
In brief:
- Dream Health Chain loses approximately $71.800 through an exploit in the award functionality.
- The attacker was able to re-claim an already claimed reward by resetting the contract.
- The problem lies in the smart contract logic, which does not record collateral or check for duplicate claims.
Flaw in the contract logic
According to research by SlowMist, a cybersecurity firm specialised in blockchain security, the vulnerability lies in three functions of the smart contract.
The createAward() function registers a fixed reward without recording any collateral. Subsequently, participateAward() cannot check whether a reward has already been claimed, allowing a claimed reward (with status 2) to be reset to status 1. Finally, claimAward() repeatedly pays out the same fixed reward from the same proxy balance.
Minimal cost for the attacker
The attacker was able to trigger this exploit with a transfer of just 0 to 1 wei, which costs practically nothing. This makes the attack vector extremely cheap to execute.
SlowMist has identified the attacker as 0xd3a8d0a9f55cf679fff6f277e49afc95b49d2b07 and traces the transaction to the proxy contract 0xe2a047aadbac51b0116af1ce91ebdae4b4202094 on the blockchain.
Not financial advice. The Latest Crypto News provides educational and informational content only. Crypto-assets are highly volatile and you can lose your entire investment. Always do your own research. Read our full disclaimer.
Affiliate disclosure. Some links on this site are affiliate links. If you sign up with a partner through one of them, we may earn a commission at no extra cost to you. This never influences our reporting. See our editorial guidelines.