Revoke.cash logo

WINR Hack

Check if your address is affected.

31 May 2024
$11k stolen
Arbitrum Logo

Around $11k (roughly 293k WINR tokens) was stolen from users of WINR Protocol (JustBet), a gaming protocol on Arbitrum. Its MixedSwapRouter accepted a caller-supplied payer address in its Algebra swap callback and pulled tokens from that address with transferFrom, without checking that the caller was a legitimate pool. An attacker triggered the callback through a fake pool with the payer set to a wallet that had approved the router, spending that approval to drain its tokens. Anyone who approved the WINR MixedSwapRouter should revoke.

Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.

Sources:x.com

Next time, revoke it automatically

Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.

See how Auto-Revoking works →
Get Ultimate
Back to Exploits