Super Sushi Samurai hack — March 2024
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | March 21, 2024 |
| Target type | Gaming or metaverse |
| Loss | $4,600,000Published estimates range $4,600,000 to $4,800,000Price at time of incident |
| Method | Contract logic errorThe SSS token contract's transfer function read the sender's balance and then wrote both the debited sender balance and the credited recipient balance without checking that the two addresses differed. Sending an entire balance to one's own address therefore doubled it, and the postCheck routine did not catch the discrepancy. The attacker started with roughly 690 million SSS and repeated the self-transfer about 25 times, then sold the resulting trillions of tokens into the liquidity pool for 1,310 ETH. |
| Chains | Blast |
| Outcome | Funds returned |
What happened
Super Sushi Samurai was a Telegram-based idle game on Blast, an Ethereum layer 2, with an associated SSS token. On 21 March 2024 an attacker exploited a logic error in the token contract's transfer function. Because the code read the sender's balance and then wrote both the debited and the credited balance without checking that sender and recipient were different addresses, transferring an entire balance to one's own address doubled it. The flaw was identified by a Yuga Labs developer known as Coffee.
The attacker acquired roughly 690 million SSS and ran about 25 self-transfers, ending with trillions of tokens, then sold them into the liquidity pool for 1,310 ETH. The SSS price fell about 99.9 percent. The project confirmed on X that it had been exploited, that the issue was mint-related, and that tokens had been minted and sold into the liquidity pool. CertiK publicly characterised the incident as a white hat rescue, and the attacker signed an on-chain message to the team offering to return the funds.
Reported losses differ. Most named coverage, and the on-chain ETH amount, put the loss at about $4.6 million, equal to 1,310 ETH; SolidityScan's technical analysis states over $4.8 million. On 24 March 2024 the team announced that the v2 pool would be restored to 1,339.50 ETH, its pre-incident level, that the white hat would receive a 5 percent ETH reward funded by the team, and that holders would be compensated by airdrop based on a snapshot taken at block 1111438. These compensation details come from a single Cointime news item republished by Bitget News and are not corroborated by the other sources here.
Sources
- DecryptSecondary · retrieved 2026-08-01
- SolidityScanSecondary · retrieved 2026-08-01
- ForkLogSecondary · retrieved 2026-08-01
- Bitget News (republished from Cointime)Aggregator · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Super Sushi Samurai hack — March 2024", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/super-sushi-samuraihttps://itokenly.com/hacks/super-sushi-samuraiPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.