The NovaBox reward pool was attacked, and hackers exploited a vulnerability in the distribution mechanism to steal 56.73 ETH

By: rootdata|2026/06/12 04:45:01
0
Share
copy

According to Bits.media, the reward pool of the NovaBox platform was hacked on June 9 on Ethereum, resulting in a loss of approximately 56.73 ETH, affecting over 130 deposit users. The attacker drained the pool's funds from 65.11 ETH to 0.09 ETH in a single transaction, accounting for about 99.86%.

Security company F12 stated that the incident was not due to a smart contract vulnerability, but rather a flaw in the reward distribution mechanism. The attacker borrowed 427.5 WETH through an Aave V3 flash loan, exploiting a loophole in NovaBox's mechanism of distributing dividends before updating balances when users deposit or withdraw. The hacker first deposited a small amount of NOVA tokens to trigger the dividend calculation, then deposited a large amount of ETH, significantly increasing the actual share. However, since the system did not update the balance in time, dividends were still calculated based on the previous small share, while payments were made based on the new large share, resulting in approximately 145.82 ETH of "phantom dividends," which drained the reward pool.

You may also like

B.AI partners with MiniMax to launch a limited-time free experience of M3, enabling zero-threshold implementation of Agentic productivity through full-stack infrastructure

B.AI and MiniMax launch a limited-time free offer for M3, allowing access to top-tier large model core computing power with no threshold.

The second half of the computing power battle: Intel CEO Pat Gelsinger reveals how AI is reshaping the global semiconductor supply chain

Intel CEO Pat Gelsinger's latest discussion: The AI computing power battle has gone beyond the single-point competition of GPUs; the ultimate trump card is to comprehensively restructure the semiconductor supply chain and solve the systemic bottlenecks in advanced manufacturing.

WEEX Live mode: Monitor 20 trading pairs at once and trade like a pro

WEEX Live mode: Multi-screen desktop layout for 20 pairs, TradingView charts, one-click layout, and smart guides. Trade like a pro now.

Morning Report | Secret Network loses $4.67 million due to cross-chain vulnerability; Michael Saylor releases Bitcoin Tracker information again, may disclose increased holdings data next week

Overview of Important Market Events on June 21

Kalshi's biggest competitor is not Polymarket

The competitive logic of the prediction market has changed.

WEEX Makes Affiliate Access Easier on the Web and in the App

WEEX now provides a smoother way to access affiliate-related pages on the web and in the app. Users can find the Affiliate entry more easily and go to the right page based on their login and affiliate status.

Popular coins

Latest Crypto News

Read more
iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com