The endCoinFlip function and throwSlammer function of the smart contract implementations for Cryptogs, an Ethereum game, generate random numbers with an old block's hash. Therefore, attackers can predict the random number and always win the game.
References
Link | Resource |
---|---|
https://medium.com/@jonghyk.song/attack-on-pseudo-random-number-generator-prng-used-in-cryptogs-an-ethereum-cve-2018-14715-f63a51ac2eb9 | Exploit Third Party Advisory |
Configurations
Information
Published : 2018-08-03 11:29
Updated : 2018-10-02 12:30
NVD link : CVE-2018-14715
Mitre link : CVE-2018-14715
JSON object : View
CWE
CWE-338
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
Products Affected
cryptogs
- cryptogs