Labs / Open the treasury door
Isolated environment·0xrange sandbox testnet
+150 XP on completion

  Stage 1 · Briefing

Parity multisig (first hack)

Parity Wallet

Parity's multisig wallet exposed an ownership-setting function that shipped without a guard stopping it from being called again on a live wallet. An attacker simply called it on three large multisigs, reassigned ownership to themselves, and withdrew ~150,000 ETH. White-hats then raced to drain the remaining at-risk wallets to safety. The root cause is exactly this lab: a privileged, state-changing function with no access control.

DateJuly 19, 2017
Impact~150,000 ETH (~$30M)
DurationA single afternoon
Attack classSmart-contract security
Timeline
Jul 2017Parity multisig wallets hold large post-ICO treasuries.
Jul 19Attacker calls the unprotected ownership function; drains 3 wallets (~150k ETH).
Jul 19A white-hat group drains the remaining vulnerable wallets to protect them.
AfterWhite-hats return the rescued funds to their original owners.
Stage 1 of 5