Predictable Random Number Generation in Cryptogs Smart Contract Implementation

Predictable Random Number Generation in Cryptogs Smart Contract Implementation

CVE-2018-14715 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:N/A:N

The endCoinFlip function and throwSlammer function of the smart contract implementations for Cryptogs, an Ethereum game, generate random numbers with an old block's hash. Therefore, attackers can predict the random number and always win the game.

Learn more about our Web Application Penetration Testing UK.