{"id":62136,"date":"2023-10-05T19:42:18","date_gmt":"2023-10-05T19:42:18","guid":{"rendered":"https:\/\/egrowonline.com\/?p=62136"},"modified":"2023-10-05T19:42:18","modified_gmt":"2023-10-05T19:42:18","slug":"friend-tech-copycat-stars-arena-patches-exploit-after-some-funds-drained","status":"publish","type":"post","link":"http:\/\/egrowonline.com\/?p=62136","title":{"rendered":"Friend\u200b.tech copycat Stars Arena patches exploit after some funds drained"},"content":{"rendered":"<p> <br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/images.cointelegraph.com\/cdn-cgi\/image\/format=auto,onerror=redirect,quality=90,width=840\/https:\/\/s3.cointelegraph.com\/uploads\/2023-10\/fd3f3a05-0a0d-47aa-9bb2-4aa62cf002b9.jpg\" \/><\/p>\n<div data-v-3d3be88a=\"\">\n<p>The Stars Arena Web3 social media app on Avalanche has lost some of its funds due to a malicious attack, according to social media reports.\u00a0<\/p>\n<p>Stars Arena user Lilitch.eth discovered the exploit on Oct. 5 and announced it on X (formerly Twitter), claiming that over $1 million was lost. The Stars Arena team confirmed the attack, calling it a \u201cwar\u201d against the app. They said the attack only resulted in approximately $2,000 in losses and that the exploit had been patched.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">THE EXPLOIT HAS BEEN FIXED.<\/p>\n<p>BUT DON\u2019T GET THIS WRONG WE ARE AT WAR.<\/p>\n<p>We\u2019re being targeted by malicious actors in the space that want to steal your money.<\/p>\n<p>The little guy is under attack. <\/p>\n<p>You are under attack.<\/p>\n<p>Your right to platform diversity is under attack.<\/p>\n<p>Don\u2019t get it\u2026 <a target=\"_blank\" href=\"https:\/\/t.co\/DmbMdf9cAq\" rel=\"noopener\">pic.twitter.com\/DmbMdf9cAq<\/a><\/p>\n<p>\u2014 Stars Arena (@starsarenacom) <a target=\"_blank\" href=\"https:\/\/twitter.com\/starsarenacom\/status\/1709934535570608172?ref_src=twsrc%5Etfw\" rel=\"noopener\">October 5, 2023<\/a><\/p><\/blockquote>\n<p>Similar to Friend.tech, Stars Arena allows users to buy \u201cshares,\u201d tokenized assets issued by content creators. The issuers can grant token owners access to exclusive content or other perks. Avalanche <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/friend-tech-clone-stars-arena-drives-surge-avalanche-avax-token\" rel=\"noopener\">has seen a surge of activity<\/a> since Stars Arena was launched, with the network\u2019s daily transaction count increasing by over 186% from Oct. 3 to 4.<\/p>\n<p>On Oct. 5, Lilitch.eth declared on X that \u201c1.1 million dollars are being drained right now because of noob devs who couldn\u2019t make a copy of Friend.tech that will work properly. If you hold ANY SHARES in StarsArena you should sell while you still can.\u201d In the post, they showed a screenshot of a smart contract that contained approximately 107,329 AVAX (<a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/avalanche-price-index\" rel=\"noopener\">AVAX<\/a>), worth over $1 million at the time.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\"><a target=\"_blank\" href=\"https:\/\/twitter.com\/starsarenacom?ref_src=twsrc%5Etfw\" rel=\"noopener\">@starsarenacom<\/a>, you fucked up<\/p>\n<p>1.1 million dollars are being drained right now because of noob devs who couldn&#8217;t make a copy of <a target=\"_blank\" href=\"https:\/\/t.co\/h7traLwG9i\" rel=\"noopener\">https:\/\/t.co\/h7traLwG9i<\/a> that will work properly<\/p>\n<p>If you hold ANY SHARES in StarsArena you should sell while you still can<\/p>\n<p>read next&#x2b07;&#xfe0f; <a target=\"_blank\" href=\"https:\/\/t.co\/HzgXvJc8ju\" rel=\"noopener\">pic.twitter.com\/HzgXvJc8ju<\/a><\/p>\n<p>\u2014 lilitch.eth (@0xlilitch) <a target=\"_blank\" href=\"https:\/\/twitter.com\/0xlilitch\/status\/1709885464209973549?ref_src=twsrc%5Etfw\" rel=\"noopener\">October 5, 2023<\/a><\/p><\/blockquote>\n<p>In response, some users accused Lilitch.eth of \u201cfudding\u201d (spreading fear, uncertainty and doubt). For example, ZSwap developer Mork <a target=\"_blank\" href=\"https:\/\/twitter.com\/subzerobuildoor\/status\/1709910942342115689\" rel=\"noopener nofollow\">claimed<\/a> that \u201cno exploiter can profit from this because the gas to run the tx is higher than the Avax extracted\u201d and that \u201cthey are proxy contracts &#8211; able to be updated.\u201d<\/p>\n<p><em><strong>Related: <\/strong><a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/eth-friend-tech-revenue-tops-10-000-eth-tvl-30-000-eth\" rel=\"noopener\"><strong>Friend.tech revenue surges over 10,000 ETH, TVL tops 30,000 ETH<\/strong><\/a><\/em><\/p>\n<p>The Stars Arena team responded with a post on X stating that \u201cTHE EXPLOIT HAS BEEN FIXED.\u201d It claimed that attackers had been spending $5 in gas to drain $1 from the app in an attempt to destroy its credibility with \u201ccoordinated FUD.\u201d The team <a target=\"_blank\" href=\"https:\/\/twitter.com\/starsarenacom\/status\/1709961420941496686\" rel=\"noopener nofollow\">held<\/a> a Twitter Spaces event to explain to users what was happening, during which it stated that only around $2,000 had been lost in the attack.<\/p>\n<p>Responding to the team\u2019s post, Lilitch.eth\u00a0<a target=\"_blank\" href=\"https:\/\/twitter.com\/0xlilitch\/status\/1709938234640466060\" rel=\"noopener nofollow\">denied<\/a> that attackers had been spending $5 in gas to drain $1. \u201cNobody was spending 5$ to get 1$ from your TVL, chill,\u201d they stated, claiming instead that attackers stopped whenever gas prices became too high to make the attack profitable. Lilitch.eth also denied waging \u201cwar\u201d against the app. In another post, they claimed to support the app now that it has been patched, <a target=\"_blank\" href=\"https:\/\/twitter.com\/0xlilitch\/status\/1709941849115570401\" rel=\"noopener nofollow\">stating<\/a>, \u201cThe conflict was resolved, we are friend now. @starsarena to the moon.\u201d<\/p>\n<p>Friend.tech users have been <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/friend-tech-sim-swap-attacks-continue-four-targeted\" rel=\"noopener\">facing a wave of SIM-swap attacks<\/a>, leaving its users and those of similar apps on edge. On Oct. 5, the Friend.tech team <a target=\"_blank\" href=\"https:\/\/cointelegraph.com\/news\/friend-tech-support-remove-login-sim-swap-hack\" rel=\"noopener\">implemented a function to remove login methods<\/a> to help combat the problem.<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/cointelegraph.com\/news\/friend-tech-copycat-starsarena-patches-exploit-after-some-funds-drained\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Stars Arena Web3 social media app on Avalanche has lost some of its funds due to a malicious attack, according to social media reports.\u00a0 Stars Arena user Lilitch.eth discovered the exploit on Oct. 5 and announced it on X (formerly Twitter), claiming that over $1 million was lost. The Stars Arena team confirmed the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":62137,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false}}},"categories":[38],"tags":[448,17197,16056,1802,17058,1351,16000,624],"class_list":["post-62136","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blockchain","tag-arena","tag-copycat","tag-drained","tag-exploit","tag-friendtech","tag-funds","tag-patches","tag-stars"],"jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"http:\/\/egrowonline.com\/wp-content\/uploads\/2023\/10\/1200_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjMtMTAvZmQzZjNhMDUtMGEwZC00N2FhLTliYjItNGFhNjJjZjAwMmI5LmpwZw.jpg","_links":{"self":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/62136","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=62136"}],"version-history":[{"count":1,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/62136\/revisions"}],"predecessor-version":[{"id":62138,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/62136\/revisions\/62138"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/media\/62137"}],"wp:attachment":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=62136"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=62136"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=62136"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}