Discover how a $155k exploit hit TrustPad's Stars Arena, exposing a critical flaw in the staking contract. Learn about the breach and its implications.
On the 7th of November 2023, TrustPad was attacked. The attack was made possible due to a logical flaw in the staking contract. Around $151k worth of tokens were stolen by the attacker.
Attacker Address: 0x1a7b15354e2f6564fcf6960c79542de251ce0dc9
Victim Contract: 0x1694d7fabf3b28f11d65deeb9f60810daa26909a
Here is the fund flow during and after the exploit. You can see more details here.
Soon after the hack, the attacker started to transfer funds to Tornado Cash. See here.
The Project acknowledged the hack via their Twitter.
Nov-06-2023 04:02:52 PM +UTC – The attacker started the attack after creating a malicious contract.
Nov-07-2023 01:56:56 AM +UTC – The attacker repeatedly called vulnerable function. This was the last transaction spotted
Nov-07-2023 12:32:42 PM +UTC – The attacker started depositing funds to Tornado Cash.
The price of the TPAD token dropped from $0.120 to $0.0016 immediately following the attack. It is currently trading at $0.0011 as of the time of writing this blog. See here.
Insufficient input validation and logical flaws have been the target of hackers for a very long time.
It is recommended for protocols to prioritize testing and fuzzing to ensure all the edge cases have been successfully mitigated.
Contents
Get updates on our community, partners, events, and everything happening across the ecosystem — delivered straight to your inbox.
Subscribe Now!
Office 104/105 Level 1, Emaar Square, Building 4 Sheikh Mohammed Bin Rashid Boulevard Downtown Dubai, United Arab Emirates P.O box: 416654
Privacy PolicyAll Rights Reserved. © 2025. QuillAudits - LLC
Office 104/105 Level 1, Emaar Square, Building 4 Sheikh Mohammed Bin Rashid Boulevard Downtown Dubai, United Arab Emirates P.O box: 416654
audits@quillaudits.comAll Rights Reserved. © 2025. QuillAudits - LLC
Privacy Policy