Cryptocurrency [loss] $345,000

On-chain message

2024-03-21 [vendor] Super Sushi Samurai [chain] ethereum
Primary Source ↗
Financial Loss $345,000 (345,000 USD)
Recovered $4.3M
Blockchain(s) Ethereum

Incident Details

Super Sushi Samurai, a new blockchain game on the Blast layer-2 blockchain was exploited for $4.6 million when an attacker discovered a vulnerability in its smart contract. A bug in the mint functionality caused users who transferred their $SSS balance to themselves to receive twice as many tokens. An attacker took advantage of this to drain $4.6 million from the project, causing the $SSS token to plummet by 99%.The attacker contacted the project shortly after the theft, claiming to be a whitehat. They wrote, “Hi team, this is a whitehat rescue hack. Let’s work on reimbursing the users.” Super Sushi Samurai later confirmed that the funds had been returned, minus a 5% “bounty”. The team also gave the whitehat an additional 2.5% in SSS tokens and land, and brought them on to the project team as a tech adviser.

Total loss estimated at $345,000.

Technical Details

Initial Attack Vector
Smart contract vulnerability exploit
Vendor / Product
Super Sushi Samurai

Timeline

  1. 2024-03-21 Breach occurred
  2. 2024-03-21 Publicly disclosed