High severity7.5NVD Advisory· Published Apr 23, 2018· Updated Jun 17, 2026
CVE-2018-10299
CVE-2018-10299
Description
An integer overflow in the batchTransfer function of a smart contract implementation for Beauty Ecosystem Coin (BEC), the Ethereum ERC20 token used in the Beauty Chain economic system, allows attackers to accomplish an unauthorized increase of digital assets by providing two _receivers arguments in conjunction with a large _value argument, as exploited in the wild in April 2018, aka the "batchOverflow" issue.
Affected products
2Patches
Vulnerability mechanics
References
6- dasp.convdExploitThird Party Advisory
- medium.com/secbit-media/a-disastrous-vulnerability-found-in-smart-contracts-of-beautychain-bec-dbf24ddbc30envdExploitThird Party Advisory
- peckshield.com/2018/04/22/batchOverflow/nvdExploitThird Party Advisory
- support.okex.com/hc/en-us/articles/360002944212-BeautyChain-BEC-Withdrawal-and-Trading-SuspendednvdThird Party Advisory
- twitter.com/OKEx_/status/987967343983714304nvdThird Party Advisory
- www.reddit.com/r/ethereum/comments/8esyg9/okex_erc20_bug/nvdIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.