Proof of Weak Hands (PoWH) Coin hacked, 866 eth stolen

in #cryptocurrency7 years ago (edited)

Recently, the Proof of Weak Hands (PoWH) coin was created and advertised itself as an autonomous and self-sustaining ponzi scheme. It was implemented as an ERC20 token on the Ethereum blockchain. It was a silly and funny coin, but it was also enticing for those chasing profits because of its promise of infinite dividends. You can read more about the coin here:

https://steemit.com/ethereum/@kingscrown/powh-the-world-s-first-autonomous-and-self-sustaining-pyramid-scheme

Within the last few hours, a bug was found within the coin's smart contract and exploited. The hackers ran away with over 866 ether.

Most believe that the bug was caused by integer overflow. The exploiters of the bug passed the largest possible integer (0xFFFFF...) into the smart contract. The result was that the exploiters could then obtain an obscenely large amount of the PoWH tokens. You can see the result of their transaction here (notice the amount of ProofOfWeakHands token they received):

https://etherscan.io/tx/0xb08fb4ec0b3c7ed15579fa65c84778296f858d48e51b86e140f5ce5350ce029f

Because of the way PoWH works, holders of the coins get dividends based on how many PoWH tokens they own. Therefore, they were able to exploit the token transfer above to steal all of the dividends, AKA all of the ether that was held in the smart contract. In total, they ran away with just over 866 ether. You can see this transaction here:

https://etherscan.io/tx/0x496c0411f52978dfd7953b7e6965465977162bfaf7b88c0c78fcdc97cd395d62

For what its worth, this exploit was not intentionally put in by the developers of PoWH in order to scam everyone. Therefore, there is an important lesson to be learned from this PoWH failure: Smart contracts are only as good as their developers. Just because smart contracts are decentralized, autonomous, and 'unmodifiable' does not mean they are safe or perfect.

Sort:  

Congratulations @bitburner! You received a personal award!

Happy Birthday! - You are on the Steem blockchain for 1 year!

Click here to view your Board

Support SteemitBoard's project! Vote for its witness and get one more award!

Congratulations @bitburner! You received a personal award!

Happy Birthday! - You are on the Steem blockchain for 2 years!

You can view your badges on your Steem Board and compare to others on the Steem Ranking

Vote for @Steemitboard as a witness to get one more award and increased upvotes!

Coin Marketplace

STEEM 0.16
TRX 0.16
JST 0.031
BTC 58969.80
ETH 2512.94
USDT 1.00
SBD 2.48