SpankChain Loses $40K in Hack Due to Smart Contract Bug

SpankChain, a cryptocurrency project focused on the adult industry, lost almost $40,000 due to a smart contract flaw on Saturday.

AccessTimeIconOct 9, 2018 at 2:00 p.m. UTC
Updated Aug 18, 2021 at 10:00 p.m. UTC

Presented By Icon

Election 2024 coverage presented by

Stand with crypto

SpankChain, a cryptocurrency project focused on the adult industry, has suffered a breach that saw almost $40,000 in ethereum (ETH) stolen.

In a blog post published Tuesday, the SpankChain team disclosed the hack, saying 165.38 ETH (worth around $38,000 at the time) had been lost at around 18:00 PST on Saturday. The intrusion, which the post said was made possible by a bug in the network's payment channel smart contract, also caused $4,000 in SpankChain's BOOTY token to be frozen.

  • Bitcoin Mining in the U.S. Will Become 'a Lot More Decentralized': Core Scientific CEO
    13:18
    Bitcoin Mining in the U.S. Will Become 'a Lot More Decentralized': Core Scientific CEO
  • Binance to Discontinue Its Nigerian Naira Services After Government Scrutiny
    05:10
    Binance to Discontinue Its Nigerian Naira Services After Government Scrutiny
  • The first video of the year 2024
    04:07
    The first video of the year 2024
  • The last regression video of the year 3.67.0
    40:07
    The last regression video of the year 3.67.0
  • It apparently took over 24 hours for the project to realize the hack had taken place, with the post stating:

    "Unfortunately, as we were in the middle of investigating other smart contract bugs, we didn't realize the hack had taken place until 7:00pm PST Sunday, at which point we took Spank.Live offline to prevent any additional funds from being deposited into the payment channels smart contract."

    Of the cryptos stolen, $9,300 worth of ETH and BOOTY belonged to users, and the remainder to the project. According to the blog post, full refunds will be "sent directly to users' SpankPay accounts, and will be available as soon as we reboot Spank.Live."

    SpankChain warned of 2–3 days' delay ahead while its developers patch the issue behind the hack, redeploy a new smart contract and fix the other contract issues that were already being worked on. Limits on the use of BOOTY tokens have also been put in place temporarily.

    So far, the team says, it seems the attack was due to a "reentrancy" bug, similar to the one that allowed a major hack of The DAO crypto project in 2016.

    "The attacker created a malicious contract masquerading as an ERC20 token, where the 'transfer' function called back into the payment channel contract multiple times, draining some ETH each time," the team said, adding that it will undertake an "in-depth investigation of the attack" in the coming days.

    SpankChain further conceded it had decided not to pay for a security audit for the payment channel contract due to the costs involved, However, "taking into account both the perception value and opportunity cost of the time spent reacting to the hack, it would have been worth it," the post says.

    The firm concluded by pledging it would improve its security practices, "making sure to get multiple internal audits for any smart contract code we publish, as well as at least one professional external audit."

    Adult content image via Shutterstock

    Disclosure

    Please note that our privacy policy, terms of use, cookies, and do not sell my personal information have been updated.

    CoinDesk is an award-winning media outlet that covers the cryptocurrency industry. Its journalists abide by a strict set of editorial policies. CoinDesk has adopted a set of principles aimed at ensuring the integrity, editorial independence and freedom from bias of its publications. CoinDesk is part of the Bullish group, which owns and invests in digital asset businesses and digital assets. CoinDesk employees, including journalists, may receive Bullish group equity-based compensation. Bullish was incubated by technology investor Block.one.


    Learn more about Consensus 2024, CoinDesk's longest-running and most influential event that brings together all sides of crypto, blockchain and Web3. Head to consensus.coindesk.com to register and buy your pass now.