Developer Coffee of Yuga Labs stated that the LP of the Telegram game Super Sushi Samurai was attacked on Blast, and its token contract had a vulnerability that would double all funds if all funds were transferred to oneself. The operation sequence is to decrease the balance from, and then set the balance of to. If the two addresses are the same, toBalance will not consider the amount decrease, but instead overwrite the balance with the initial balance and transfer balance. The attacker doubled the funds through multiple loops and sold them all, obtaining 1310 ETH from the LP. In addition, according to CertiK monitoring, Super Sushi Samurai lost about $4.6 million.
All Comments