Post
Topic
Board Gambling
Merits 1 from 1 user
Re: bustabit – The original crash game
by
StackGambler
on 11/04/2019, 04:22:44 UTC
⭐ Merited by malevolent (1)
Earlier today, an attacker exploited a previously unknown vulnerability in one of bustabit's API methods which allowed him to find out the current game's outcome before its end. By exploiting this bug the attacker managed to win a total of 122.5686 BTC and empty the hot wallet.

Was the bug or the method of exploiting it in any way interesting?

It was a stupid mistake where the API exposed the game bust value before the round ended, if the player was in it.