"PlayDapp exploit continues into 4th day, with losses reaching $290M"
Primary Source ↗Incident Details
The South Korean blockchain gaming platform PlayDapp was hacked on February 9, and an attacker minted 200 million $PLA tokens. These were notionally priced at around $36.5 million, although because only 577 million $PLA were in circulation before the unauthorized mint, there would not have been sufficient liquidity for the attacker to sell them at around that price.Days after the initial attack, on February 12, the attacker minted another 1.59 billion $PLA. This has led to news reports that the platform was exploited for “$290 million”. However, this value is being naively calculated based on the token price without taking into account the massive supply inflation, and ignoring that that dollar figure is more than 2.5x the total claimed market cap of the token. Even reputable outlets like Bleeping Computer have printed the figure in their headline (though Bleeping Computer later changed the headline to a more accurate one).PlayDapp sent on-chain messages to the attacker, offering a bounty, but the offer was ignored.
Total loss estimated at $36,500,000.
Technical Details
- Initial Attack Vector
- Smart contract exploit / hack
- Vendor / Product
- PlayDapp crypto gaming platform
Timeline
- 2024-02-09 Breach occurred
- 2024-02-09 Publicly disclosed