BEC Meimi found that the value of a major vulnerability was almost zero, and OKEx suspended BEC withdrawals and transactions
36氪
2018-04-23 08:20
本文约1049字,阅读全文需要约4分钟
A "bloody case" caused by one line of code.

secondary title

The "bloody case" caused by one line of code

The transaction record operated by hackers yesterday is 0xad89ff16fd1ebe3a0a7cf4ed282302c06626c1af33221ebe0d3a470aba4a660f.

System data shows that the hacker used the data overflow vulnerability in the Ethereum ERC-20 smart contract to transfer out of thin air 57,896,044,618,658,100,000,000,000,000,000,000,000,000,000,000,000,000,000,000.792003956 564819968 BECs. The number of transfers far exceeded the total number of BEC issued by 7 billion, and the market suddenly fell into a crazy sell-off, and the market value of BEC of nearly 6.5 billion yuan almost instantly returned to zero.

The reason for the successful attack is that a certain piece of code of BEC forgot to use the safeMath method, resulting in an integer overflow vulnerability in the system. According to the security report released by the PeckShield team early this morning, hackers used the in-the-wild (a means of grabbing vulnerabilities from code) method to grab vulnerabilities from BEC programs and launch attacks.

secondary title

OKEx suspends trading urgently, US chain rolls back data

Affected by this drastic change, OKEx immediately issued an announcement in the afternoon, saying that due to abnormal BEC transactions, the exchange has suspended BEC transactions and withdrawals.

At the same time, the US chain also issued an announcement, saying that the system will roll back the transaction:

secondary title

Meitu has yet to comment on the matter

Although Cai Wensheng, CEO of Meitu, previously denied that BEC was a Meitu token, saying that BEC has nothing to do with Meitu and is a blockchain product developed by a third-party independent organization, but in fact BEC and Meitu are still inextricably linked. .

According to Cai Wensheng on February 23, Meitu’s overseas application product BeautyPlus has a promotion cooperation with it overseas.

As early as February 13, Meitu launched a digital currency wallet called "BEC Wallet", which is its first product in the layout of the blockchain. According to reports, the BEC wallet supports ETH and Ethereum ERC20 standard tokens.

The digital currency exchange that BEC launched for the first time is OKEx, which is currently the only exchange that BEC has launched. And Cai Wensheng is one of the investors of OKEx.

So far, Meitu has not commented on the matter.

36氪
作者文库