Stars Arena Incident Analysis
ID: 9350e412-eb64-54fd-a63f-487764d9dea5
STIX ID: report--9350e412-eb64-54fd-a63f-487764d9dea5
Feed Name: CertiK Blog
On 7 October 2023 Stars Arena, a SocialFi project on the Avalanche chain, was exploited via a reentrancy vulnerability that let an attacker (0xa2Ebf3FCD757e9BE1E58B643b6B5077D11b4ad7A) convert a 1 AVAX deposit into 266,103 AVAX (~$2.88M) by using a call() callback to reenter the contract, modify a pricing multiplier, and then execute sellShares; funds were subsequently dispersed to 266 EOAs. The report provides transaction and contract addresses, a decompiled-based attack flow analysis, notes a prior smaller exploit on 5 October by the same actor, and recommends standard mitigations (Checks→Effects→Interactions and Reentrancy Guards).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
