The NovaBox reward pool was attacked, and hackers exploited a vulnerability in the distribution mechanism to steal 56.73 ETH
According to Bits.media, the reward pool of the NovaBox platform was hacked on June 9 on Ethereum, resulting in a loss of approximately 56.73 ETH, affecting over 130 deposit users. The attacker drained the pool's funds from 65.11 ETH to 0.09 ETH in a single transaction, accounting for about 99.86%.
Security company F12 stated that the incident was not due to a smart contract vulnerability, but rather a flaw in the reward distribution mechanism. The attacker borrowed 427.5 WETH through an Aave V3 flash loan, exploiting a loophole in NovaBox's mechanism of distributing dividends before updating balances when users deposit or withdraw. The hacker first deposited a small amount of NOVA tokens to trigger the dividend calculation, then deposited a large amount of ETH, significantly increasing the actual share. However, since the system did not update the balance in time, dividends were still calculated based on the previous small share, while payments were made based on the new large share, resulting in approximately 145.82 ETH of "phantom dividends," which drained the reward pool.
You may also like
Do you want to buy CRCL?
Wosh: Inflation has cooled in recent weeks, AI is reshaping the economy, and forward guidance has lost its necessity
The most secretive AI winner
Looking at Stripe's ambitions and the future of stablecoins from OUSD
From Pump.fun to Collector Crypt: Has Solana's income throne changed hands?
Dan Bin's latest speech: Don't miss out on a great era
Robinhood launches its own blockchain, no longer wanting to be a tenant on others' chains
Why Tokenized Stocks Are Booming in 2026 While Crypto Is Still Struggling
Former ByteDance employee's account: How I started with two Pinduoduo hard drives and made six times the profit with Seagate to achieve financial freedom?
MiCA reshuffle begins, Binance temporarily bids farewell to the EU
How does Gate redo "buying and selling stocks" from the cryptocurrency world to the stock market?
Visa and Mastercard join 140 giants to launch a new stablecoin, but the impact on the market landscape may still be limited
Circle CEO responds to OUSD's challenge: Stablecoins are a winner-takes-all business, and we will not slow down
Argentina vs Cape Verde: When a Record-Breaking Legend Meets an Unbreakable Underdog
WEEX exclusive pre-match analysis of Argentina vs Cape Verde, exploring Messi-led Argentina’s dominance and Cape Verde’s historic defensive breakout, with a breakdown of volatility, structure, and match dynamics.
