Tweets by PeckShield
Primary Source ↗Incident Details
The brand new Arbitrum-based defi casino GMBL.COMPUTER was exploited for around 471 ETH ($770,000). The project, which promises to “generate yield from casino games”, had officially launched only hours earlier. The GMBL team later stated that they believed the exploit was due to a flaw in the platform’s referral system, where people could place bets without depositing any funds and use them to generate referral bonuses.GMBL offered a “bug bounty” to the attacker, inviting them to return 90% of the stolen funds in exchange for a promise not to pursue legal action. The exploiter later returned 235 ETH ($382,000), or half what they had stolen.GMBL promised that “we are going to thoroughly test everything again before re launching”.
Total loss estimated at $770,000.
Technical Details
- Initial Attack Vector
- Smart contract exploit / hack
- Vendor / Product
- GMBL.COMPUTER
Timeline
- 2023-09-05 Breach occurred
- 2023-09-05 Publicly disclosed