Cryptocurrency [loss] $36M+

"PlayDapp exploit continues into 4th day, with losses reaching $290M"

2024-02-09 [vendor] PlayDapp crypto gaming platform [chain] ethereum
Primary Source ↗
Financial Loss $36.5M (36,500,000 USD)
Blockchain(s) Ethereum

Incident Details

The South Korean blockchain gaming platform PlayDapp was hacked on February 9, and an attacker minted 200 million $PLA tokens. These were notionally priced at around $36.5 million, although because only 577 million $PLA were in circulation before the unauthorized mint, there would not have been sufficient liquidity for the attacker to sell them at around that price.Days after the initial attack, on February 12, the attacker minted another 1.59 billion $PLA. This has led to news reports that the platform was exploited for “$290 million”. However, this value is being naively calculated based on the token price without taking into account the massive supply inflation, and ignoring that that dollar figure is more than 2.5x the total claimed market cap of the token. Even reputable outlets like Bleeping Computer have printed the figure in their headline (though Bleeping Computer later changed the headline to a more accurate one).PlayDapp sent on-chain messages to the attacker, offering a bounty, but the offer was ignored.

Total loss estimated at $36,500,000.

Technical Details

Initial Attack Vector
Smart contract exploit / hack
Vendor / Product
PlayDapp crypto gaming platform

Timeline

  1. 2024-02-09 Breach occurred
  2. 2024-02-09 Publicly disclosed