New ceoAnyone Bug Identified in... CVE-2018-11329 CNNVD-201805-750

5.0 AV AC AU C I A
发布: 2018-05-22
修订: 2020-06-17

Our vulnerability-scanning system at PeckShield has so far discovered several dangerous smart contract vulnerabilities ( batchOverflow[1], proxyOverflow[2], transferFlaw[3], ownerAnyone[4], multiOverflow[5], burnOverflow[6]). These vulnerabilities typically affect various tokens that may be publicly traded in exchanges. Today, we would like to report a new vulnerability named ceoAnyone, which affects, instead of tradable tokens in exchanges, but Crypto-Games. Starting from the end of 2017, blockchain-based crypto-games have become popular especially with the initial success of [CryptoKitties](https://www.cryptokitties.co/). Among crypto-games, cypto idle game is an interesting category that enables players to make money by idling for hours, then followed by a profit-making transaction (e.g., selling a Lab Rat on [Ether Goo](https://ethergoo.io/)). Many of the cypto idle game owners make profit from the transaction fee. However, what if the owner address could be manipulated or...

0%
暂无可用Exp或PoC
当前有1条受影响产品信息