{"id":60943,"date":"2023-10-06T04:33:40","date_gmt":"2023-10-06T08:33:40","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=60943"},"modified":"2023-10-06T04:33:43","modified_gmt":"2023-10-06T08:33:43","slug":"stars-arena-developers-address-exploit-dispel-coordinated-fud","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/stars-arena-developers-address-exploit-dispel-coordinated-fud\/","title":{"rendered":"Stars Arena Developers Address Exploit, Dispel Coordinated FUD"},"content":{"rendered":"\n<p>A flaw in the Stars Arena price function <a href=\"https:\/\/coinscreed.com\/staging\/crypto-users-lose-over-4m-through-phishing-urls-on-google-ads.html\" target=\"_blank\" rel=\"noreferrer noopener\">enabled hackers to steal <\/a>approximately $2,000; however, the flaw has since been rectified.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"443\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/mn-1024x443.jpg\" alt=\"\" class=\"wp-image-60945\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/mn-1024x443.jpg 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/mn-300x130.jpg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/mn-768x332.jpg 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/mn-1536x664.jpg 1536w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/mn-18x8.jpg 18w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/mn-1320x571.jpg 1320w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/mn-750x324.jpg 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/mn-1140x493.jpg 1140w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/mn.jpg 1600w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Stars Arena Developers Address Exploit, Dispel Coordinated FUD<\/figcaption><\/figure>\n\n\n\n<p>After patching an exploit that allowed attackers to steal $2,000 from the Avalanche-based decentralized social media platform, the team behind the new Friend. Tech-inspired protocol Stars Arena derided &#8220;coordinated FUD&#8221; as unfounded.<\/p>\n\n\n\n<p>In a tweet dated October 5, the Stars Arena account stated that the exploit had been patched and added, &#8220;Don't get this wrong, we are at war.&#8221;<\/p>\n\n\n\n<blockquote class=\"twitter-tweet\"><p lang=\"en\" dir=\"ltr\">THE EXPLOIT HAS BEEN FIXED.<br><br>BUT DON\u2019T GET THIS WRONG WE ARE AT WAR.<br><br>We\u2019re being targeted by malicious actors in the space that want to steal your money.<br><br>The little guy is under attack. <br><br>You are under attack.<br><br>Your right to platform diversity is under attack.<br><br>Don\u2019t get it\u2026 <a href=\"https:\/\/t.co\/DmbMdf9cAq\" target=\"_blank\">pic.twitter.com\/DmbMdf9cAq<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a><\/p>&mdash; Stars Arena (@starsarenacom) <a href=\"https:\/\/twitter.com\/starsarenacom\/status\/1709934535570608172?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">October 5, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote> \n\n\n\n<p>&#8220;0xlilitch&#8221; of X claimed that Stars Arena's &#8220;noob devs&#8221; failed to patch a vulnerability in the platform's price function, enabling attackers to sell &#8220;tickets&#8221; to zero users in exchange for technically free Avalanche AVAX tokens.<\/p>\n\n\n\n<blockquote class=\"twitter-tweet\"><p lang=\"en\" dir=\"ltr\"><a href=\"https:\/\/twitter.com\/starsarenacom?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">@starsarenacom<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a>, you fucked up<br><br>1.1 million dollars are being drained right now because of noob devs who couldn&#039;t make a copy of <a href=\"https:\/\/t.co\/h7traLwG9i\" target=\"_blank\">https:\/\/t.co\/h7traLwG9i<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> that will work properly<br><br>If you hold ANY SHARES in StarsArena you should sell while you still can<br><br>read next\u2b07\ufe0f <a href=\"https:\/\/t.co\/HzgXvJc8ju\" target=\"_blank\">pic.twitter.com\/HzgXvJc8ju<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; lilitch.eth (@0xlilitch) <a href=\"https:\/\/twitter.com\/0xlilitch\/status\/1709885464209973549?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">October 5, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote> \n\n\n\n<p>However, the attackers reportedly found the assault vector to be economically unfeasible. The exploit caused a significant increase in Avalanche's gas prices, making extracting the earnings from the breach considerably more costly than anticipated.<\/p>\n\n\n\n<p>Consequently, the assailants allegedly spent more on gas fees than they made from the exploit. In an X post, the CEO of Ava Labs, Emin G\u00fcn Sirer, noted that for every $0.04 earned from the exploit, the hackers spent an average of $0.25.<\/p>\n\n\n\n<blockquote class=\"twitter-tweet\"><p lang=\"en\" dir=\"ltr\">So much FUD about a Stars Arena exploit that has (1) already been fixed, (2) cost the attacker $0.25 to make $0.04, and (3) the attacker extracted a sum total of only $2,000. Now that it&#039;s over, let&#039;s get back to having fun in the arena.<\/p>&mdash; Emin G\u00fcn Sirer\ud83d\udd3a (@el33th4xor) <a href=\"https:\/\/twitter.com\/el33th4xor\/status\/1709923165919387999?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">October 5, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote> \n\n\n\n<p>Despite the relatively unsuccessful exploit, crypto community members were eager to retaliate against the Stars Arena team. &#8220;Foobar,&#8221; the pseudonymous founder and developer of Delegate, criticized the platform, alleging that it botched its Friend. Tech fork and instructed Stars Arena to \u201cdelete your account and product, clownshow.\u201d<\/p>\n\n\n\n<blockquote class=\"twitter-tweet\"><p lang=\"en\" dir=\"ltr\">THE EXPLOIT HAS BEEN FIXED.<br><br>BUT DON\u2019T GET THIS WRONG WE ARE AT WAR.<br><br>We\u2019re being targeted by malicious actors in the space that want to steal your money.<br><br>The little guy is under attack. <br><br>You are under attack.<br><br>Your right to platform diversity is under attack.<br><br>Don\u2019t get it\u2026 <a href=\"https:\/\/t.co\/DmbMdf9cAq\" target=\"_blank\">pic.twitter.com\/DmbMdf9cAq<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a><\/p>&mdash; Stars Arena (@starsarenacom) <a href=\"https:\/\/twitter.com\/starsarenacom\/status\/1709934535570608172?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">October 5, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote> \n\n\n\n<p>Stars Arena is the most recent addition to a roster of social finance platforms, including Alpha on the Bitcoin network, Friendzy on Solana, and PostTech on Arbitrum.<\/p>\n\n\n\n<p>Despite the proliferation of similar DeSo apps, <a href=\"https:\/\/www.friend.tech\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Friend.Tech<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> continues to dominate the market with over $293 million monthly trading volume, surpassing PostTech by over $283 million.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A flaw in the Stars Arena price function enabled hackers to steal approximately $2,000; however, the flaw has since been rectified. After patching an exploit that allowed attackers to steal $2,000 from the Avalanche-based decentralized social media platform, the team behind the new Friend. Tech-inspired protocol Stars Arena derided &#8220;coordinated FUD&#8221; as unfounded. In a [&hellip;]<\/p>\n","protected":false},"author":53,"featured_media":60945,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21,130],"tags":[6366,5508,16607,16661],"class_list":["post-60943","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-blockchain-news","tag-avalanche-news","tag-blockchain-2","tag-hacks-2","tag-stars-arena"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/mn.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/60943","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/53"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=60943"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/60943\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/60945"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=60943"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=60943"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=60943"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}