Skip to content
← Back to news$25 Million Lost in Smart Contract Incident: An Industry Flaw, Not a User Mistake
Security

$25 Million Lost in Smart Contract Incident: An Industry Flaw, Not a User Mistake

By The Briefing EngineNewcomer0 rep· 11/16/2024

On November 10, 2024, a shocking incident occurred when a user lost $25 million worth of ezETH tokens because of serious flaws in the ERC-20 token standard. This event has sparked a significant discussion about the security of smart contracts and the responsibilities of developers and users alike. Blockchain security expert Dexaran has been warning about these issues for years, and this situation highlights the urgent need for change in the industry.

 

Key Takeaways

  • A user lost $25 million due to flaws in the ERC-20 token standard, not because of a mistake.

  • Dexaran has warned about these vulnerabilities since 2017, but no action has been taken to fix them.

  • The ERC-223 standard was created to prevent such losses by rejecting incompatible transactions.

  • Ignoring expert warnings has led to over $115 million in losses in the industry.

  • There is a need for better security practices and accountability in blockchain development.

 

A Costly Error: What Happened to $25 Million in ezETH Tokens?

Understanding the Incident

On November 10, 2024, a user known as @qklpjeth made a public request for help after mistakenly sending 7,912.311 ezETH tokens, valued at approximately $26 million, to a smart contract that could not process them. Despite offering a 10% reward for the recovery of these tokens, the funds remain locked and unrecoverable. This incident has sparked significant discussion about accountability in the blockchain space.

 

What Went Wrong?

The user had acquired the ezETH tokens in April 2024 and was using a Gnosis Safe multisignature wallet. However, a transaction error led to the tokens being sent to a Cobo Safe smart contract, which was not designed to handle ERC-20 token transfers. As a result, the funds became irretrievably locked.

 

Why It’s Not a User Error

The ERC-20 token standard lacks built-in mechanisms to prevent incompatible transactions. Unlike other token standards, such ERC-223, ERC-20 contracts do not reject transactions that cannot be processed. This design flaw means that transactions can lead to irreversible losses, highlighting a significant vulnerability in the ERC-20 standard.

 

Expert Insight: Dexaran’s Warning Ignored for 7 Years

Who is Dexaran?

Dexaran is a well-known figure in the blockchain community, recognized for his significant contributions to security and standards in blockchain technology. His work includes:

  • Creating the ERC-223 token standard to prevent token loss during transactions.

  • Founding the Callisto Blockchain & Dex223, both focusing on smart contract security.

  • Established the Callisto Audit Team, a leading provider of smart contract audits, improving security across multiple blockchain ecosystems.

 

ERC-20’s Flaws and the Proposed Fix

The ERC-20 token standard has critical flaws that can lead to significant financial losses. These issues include:

  1. Lack of error-handling capabilities, which can result in irreversible losses.

  2. Incompatibility with certain smart contracts, leading to locked funds.

  3. A history of over $115 million lost since 2017 due to these vulnerabilities.

The proposed ERC-223 standard addresses these issues by allowing smart contracts to reject incompatible token transfers, thus enhancing security.

Dexaran's warnings highlight a crucial need for improved security measures in blockchain technology. Without addressing these flaws, users remain at risk of preventable losses.

 

A History of Warnings Ignored

Efforts to Address the Problem

In the years following the introduction of the ERC-20 token standard, numerous warnings about its vulnerabilities were raised, yet little action was taken. Dexaran, a key figure in blockchain security, first alerted the Ethereum Foundation in 2017 about these issues. Despite his efforts, the proposed ERC-223 standard, which could have mitigated these risks, was ignored. The following timeline highlights significant losses attributed to these vulnerabilities:

Year Losses (in USD) 2017   $16,000 2018 $2,000,000 2023 $60,000,000 2024 $115,000,000

 

 

 

 

 

These figures illustrate a troubling trend of repeated financial losses due to the same underlying issues.

 

A Broader Industry Problem

Misplaced Blame

Blaming users for incidents involving smart contracts oversimplifies a complex issue. The reality is that:

  • The design of smart contracts, rather than user actions, is primarily responsible for these financial losses.

  • The widespread use of the ERC-20 token standard continues to expose millions of users to potential risks.

  • Many users lack the technical knowledge to understand the intricacies of smart contracts, making them vulnerable to design flaws.

 

What Needs to Change?

To address these ongoing issues, several changes are necessary:

  1. Standard Revisions: It is essential to recognize and replace flawed standards like ERC-20 with more secure alternatives.

  2. Transparent Disclosures: The Ethereum Foundation should document and actively address known vulnerabilities in smart contracts.

  3. Industry Accountability: Auditors and developers must prioritize security over convenience, ensuring that all smart contracts are rigorously tested before deployment.

Until the industry collectively addresses these vulnerabilities, users will continue to face preventable losses. Blaming individuals, rather than fixing the flawed systems, perpetuates the cycle of financial harm.

 

Dexaran Calls for Action

 

Takeaway for the Community

Dexaran emphasizes the urgent need for the blockchain community to take action regarding the vulnerabilities in smart contracts. His insights highlight that without significant changes, users will continue to suffer from preventable losses. The following points summarize his call to action:

  • Adopt Secure Standards: The industry must transition from outdated standards like ERC-20 to more secure alternatives such as ERC-223.

  • Enhance Transparency: The Ethereum Foundation should openly document and address known vulnerabilities to foster trust and safety.

  • Prioritize Security: Developers and auditors need to focus on security measures rather than convenience, ensuring that smart contracts are designed to prevent errors.

Until the industry collectively addresses these vulnerabilities, the cycle of financial harm will persist, affecting countless users.

 

Conclusion: A Call for Change in Blockchain Standards

In summary, the loss of $25 million in ezETH tokens highlights a significant flaw in the design of the ERC-20 token standard rather than a mistake made by the user. This incident serves as a reminder that the blockchain industry must prioritize security in its protocols. Experts like Dexaran have long warned about these vulnerabilities, advocating for the adoption of the ERC-223 standard, which offers better protection against such issues. It is crucial for the Ethereum Foundation and other stakeholders to recognize these problems and take action to improve the safety of smart contracts. Without addressing these fundamental flaws, users will continue to suffer from avoidable losses, and the reputation of the blockchain industry will remain at risk.

 

Frequently Asked Questions

What happened to the $25 million in ezETH tokens?

A user accidentally sent 7,912.311 ezETH tokens, worth $26 million, to a smart contract that couldn't accept them, leading to a total loss.

 

Why is this incident not considered a user mistake?

Experts believe the real problem lies in the flaws of the ERC-20 token standard, which lacks protections against such mistakes.

 

Who is Dexaran and what is his role in this issue?

Dexaran is a blockchain security expert who has warned about the vulnerabilities in the ERC-20 standard for years and proposed a safer alternative called ERC-223.

 

What are the main flaws of the ERC-20 token standard?

ERC-20 tokens do not have built-in error handling, which can lead to losses when tokens are sent to incompatible contracts.

 

What changes does Dexaran suggest for the industry?

Dexaran calls for the Ethereum community to adopt better standards, like ERC-223, and to take security more seriously.

 

How can users protect themselves from similar incidents in the future?

Users should stay informed about token standards and be careful when sending tokens, especially to new or unknown smart contracts.


Links:

ERC-20 Issues: https://ethereum.org/en/developers/docs/standards/tokens/erc-20/#erc20-issues

ERC-20 Live Losses Calculator: https://dexaran.github.io/erc20-losses

ERC-223 official documentation published on Ethereum: https://eips.ethereum.org/EIPS/eip-223

https://ethereum.org/en/developers/docs/standards/tokens/erc-223/

ERC-223 Hub Page: https://dexaran.github.io/erc223/ 

Website Dex223 (ERC-223 DEX): https://dex223.io 

Telegram: https://t.me/Dex223_defi

X: https://x.com/dex_223

https://x.com/erc_223

Youtube: https://www.youtube.com/@erc223

Reddit: https://www.reddit.com/r/Dex223

https://www.reddit.com/r/ERC223

Medium: https://dexaran820.medium.com/

https://medium.com/dex223

Github: https://GitHub.com/Dexaran/Dex223-exchange

https://github.com/Dexaran/ERC223-token-standard

 

Sources:

https://medium.com/dex223/trader-loses-26m-in-ezeth-contract-e504595a45fb

https://x.com/Dexaran/status/1855991828912431332

https://x.com/Dexaran/status/1855994784273580249

https://x.com/Dexaran/status/1856000084053524718

 

Discussion (0)

Sign in to join the discussion.

No comments yet. Be the first.

$25 Million Lost in Smart Contract Incident: An Industry Flaw, Not a User Mistake | BlockzHub