The team behind a Telegram-based game said Thursday that it is working with an apparent white hat hacker to return funds to users after $4.6 million worth of tokens was stolen due to an exploit.
The hacker hit the newly launched game Super Sushi Samurai, which minted its tokens on Ethereum scaling network Blast. The price of its native token, SSS, plunged to a tiny fraction of a penny on the reports of the hack, which exploited a token transfer bug within the smart contract that powers the game.
A pseudonymous Yuga Labs smart contract developer who goes by the name Coffee said on Twitter (aka X) that the bug allowed exploiters to boost their holdings. “Transferring your entire balance to yourself doubles it,” they wrote.
Security firm CertiK spotted the exploit and said on Twitter that it was a white hat rescue. White hat rescues are when a protocol is exploited by a hacker in order to show those behind the project that they have a vulnerability. The noble exploiter then is typically rewarded and allowed to keep a share of the swiped funds.
“We’re working with the white hat on the safe return of funds,” Super Sushi Samurai said on X/Twitter hours after the hack. “An update and postmortem will follow.” The team behind the game did not immediately respond to Decrypt’s questions.
Cielo.Finance, which tracks blockchain data, told Decrypt that SSS tokens were snapped up after the hack. Traders will often do that in case a white hack returns funds and the price of the tokens then rises.
We're working with the white hat on the safe return of funds. An update and post-mortem will follow.
Super Sushi Samurai is a simple “idle” game that runs within the instant messaging platform, Telegram—much like Notcoin, a recent crypto gaming sensation. Currently limited to players who have an access code, Super Sushi Samurai sees players' cartoonish warriors fight foes to earn token rewards, plus there are NFT land plots that play into "megawar" battles between clans.
I wasn’t expecting to enjoy Notcoin. To be honest, I was pretty dismissive at first. You tap an image of a coin on your mobile device, earn an in-game currency for each tap, and are bound by an energy bar that depletes as you tap (and refills when idle). And in the end, you'll be entitled to an airdrop of an upcoming token based on your tapping abilities.
It sounded pretty dull. So imagine my surprise that three weeks after trying the game for the first time, I’m still opening it up every mornin...
It runs on Ethereum layer-2 network Blast, a scaling network which aims to make it quicker and cheaper for people to do things on the sometimes slow and costly mainnet. Blast just launched its mainnet on February 29, but already faced a significant technical hurdle last week when it briefly stopped producing blocks following the Ethereum network's Dencun upgrade.
Decentralized exchange Bunni has announced it is permanently shutting down following an $8.4 million hack last month, with founders saying they lack the capital needed for a secure relaunch that would cost six to seven figures in audit and monitoring expenses alone.
Bunni announced the permanent shutdown on Wednesday, citing insurmountable recovery costs following the attack that exploited the platform's Liquidity Density Function across two pools, weETH/ETH on Unichain and USDC/USDT on Ethereum...
The Ethereum Foundation moved more than 160,000 ETH—valued at approximately $610 million as of this writing—to another wallet on Tuesday, prompting speculation over the reasons and destination for the bulk of the Foundation’s treasury.
On Wednesday, the Safe Foundation and the Ethereum Foundation announced that the funds had been moved into a multi-signature Safe Wallet, which is designed to secure the funds. Ethereum Foundation Co-Executive Director Hsiao-Wei Wen confirmed on X on Tuesday that...
Crypto users earlier today spotted Solana founder Anatoly Yakovenko uploading code on Github for what appeared to be his own decentralized perpetual futures exchange, leading to mass speculation that a new Hyperliquid competitor could be coming to Solana.
But Yakovenko has since poured cold water on the idea, clarifying that he was just “messing around” with the AI tool Claude and made the repo on Github public by accident. Still, he’s urging other developers to “steal the idea” and run with it....