{"id":61027,"date":"2023-10-07T16:44:53","date_gmt":"2023-10-07T20:44:53","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=61027"},"modified":"2023-10-07T16:47:17","modified_gmt":"2023-10-07T20:47:17","slug":"stars-arena-confirms-protocol-exploit","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/stars-arena-confirms-protocol-exploit\/","title":{"rendered":"Stars Arena Confirms Protocol Exploit"},"content":{"rendered":"\n<p>Friend Tech's rival company, Stars Arena has acknowledged the <a href=\"https:\/\/coinscreed.com\/staging\/web3-platform-galxe-protocol-experiences-dns-attack.html\" target=\"_blank\" rel=\"noreferrer noopener\">protocol attack<\/a> that depleted more than 266,000 AVAX tokens.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/croc_1696704241983-1024x576.jpg\" alt=\"Stars Arena Confirms Protocol Exploit\" class=\"wp-image-61029\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/croc_1696704241983-1024x576.jpg 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/croc_1696704241983-300x169.jpg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/croc_1696704241983-768x432.jpg 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/croc_1696704241983-18x10.jpg 18w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/croc_1696704241983-750x422.jpg 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/croc_1696704241983-1140x641.jpg 1140w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/croc_1696704241983.jpg 1200w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Stars Arena Confirms Protocol Exploit<\/figcaption><\/figure>\n\n\n\n<p>Recently, Stars Arena, the Avalanche-based adversary of social protocol Friend Tech, confirmed a protocol vulnerability. This led to the astounding loss of 266,103 AVAX tokens, valued at almost $2.88 million.<\/p>\n\n\n\n<p>The <a href=\"https:\/\/coinscreed.com\/staging\/nft-connect-musical-communities-to-blockchain-ecosystems.html\" target=\"_blank\" rel=\"noreferrer noopener\">blockchain ecosystem <\/a>and the safety and security of smart contracts have come under scrutiny in the wake of this shocking disclosure that has shocked the cryptocurrency community.<\/p>\n\n\n\n<p>In a message posted on social networking site X, Stars Arena expressed sincere remorse for the event and let people know that DDOS was attacking the platform. <\/p>\n\n\n\n<p>The severity of the situation was highlighted by <a href=\"https:\/\/coinscreed.com\/staging\/nvirworld-collaborates-with-certik-to-enhance-security.html\" target=\"_blank\" rel=\"noreferrer noopener\">Blockchain analytics company CertiK<\/a>, who also offered information on the nature of the exploit. In a recent post on the X platform, CertiK called attention that the attack that struck Stars Arena was referred to as a &#8220;reentrancy exploit.&#8221; This attack happens when nefarious parties invoke a weak smart contract numerous times within a single transaction.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\"><a href=\"https:\/\/twitter.com\/hashtag\/CertiKSkynetAlert?src=hash&ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">#CertiKSkynetAlert<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> \ud83d\udea8<br><br>Stars Arena have been exploited for 266,103 AVAX (~S2.88m) via reentrancy exploit.<br><br>The funds currently sit in EOA 0xa2E which was also involved in an exploit on Stars Arena on 05 October.<a href=\"https:\/\/t.co\/vYWresLAnB\" target=\"_blank\">https:\/\/t.co\/vYWresLAnB<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; CertiK Alert (@CertiKAlert) <a href=\"https:\/\/twitter.com\/CertiKAlert\/status\/1710580938969633176?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">October 7, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>In the case of Stars Arena, the attacker tricked the smart contract of the software to steal a sizable sum of AVAX tokens. The weak smart contract opened the door for reentrancy problems by allowing the transfer of <a href=\"https:\/\/www.bing.com\/search?pglt=41&q=Stars+Arena+Confirms+Protocol+Exploit&cvid=958c64ba00a749acbfba220d682ca8ce&gs_lcrp=EgZjaHJvbWUyBggAEEUYOTIGCAEQRRg90gEHNDI3ajBqMagCALACAA&FORM=ANNTA1&PC=WSEDDB\" target=\"_blank\" rel=\"noreferrer noopener\">platform-native tokens<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> (AVAX) to external contracts.<\/p>\n\n\n\n<p>Notably, CertiK offered more information about the attacker's strategy. Notably, the attacker changed the values in the smart contract that have an impact on price acquisition. <\/p>\n\n\n\n<p>They were able to sell tokens for a greatly inflated price as a result of doing this. Surprisingly, the address used, 0xa2E, has been used for similar vulnerabilities before. Earlier this week, Stars Arena was the target of an exploit involving this Ethereum address.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-stars-arena-s-response\">Stars Arena's Response<\/h2>\n\n\n\n<p>Stars Arena is interacting with its community in response to the exploit, reiterating its dedication to finding a solution. The platform is actively developing a way to get the money back and protect its smart contracts from further intrusions. <\/p>\n\n\n\n<p>The protocol has promised to keep users informed about its efforts and has thanked the community for its unwavering support throughout this trying time.<\/p>\n\n\n\n<p>The launch of Stars Arena on the<a href=\"https:\/\/coinscreed.com\/staging\/curatedao-launches-pinterest-like-database-platform-on-avalanche-blockchain.html\" target=\"_blank\" rel=\"noreferrer noopener\"> Avalanche blockchain <\/a>has had a significant impact on AVAX's pricing and network activity. The price increase suggests that market participants welcomed the announcement of the opening of Stars Arena.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Friend Tech&#8217;s rival company, Stars Arena has acknowledged the protocol attack that depleted more than 266,000 AVAX tokens. Recently, Stars Arena, the Avalanche-based adversary of social protocol Friend Tech, confirmed a protocol vulnerability. This led to the astounding loss of 266,103 AVAX tokens, valued at almost $2.88 million. The blockchain ecosystem and the safety and [&hellip;]<\/p>\n","protected":false},"author":43,"featured_media":61029,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11476],"tags":[16661,2156,12002],"class_list":["post-61027","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacks-and-scams","tag-stars-arena","tag-exploit","tag-hacks"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/10\/croc_1696704241983.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/61027","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/43"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=61027"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/61027\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/61029"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=61027"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=61027"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=61027"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}