High severity7.5NVD Advisory· Published Sep 24, 2018· Updated Jun 17, 2026
CVE-2018-12975
CVE-2018-12975
Description
The random() function of the smart contract implementation for CryptoSaga, an Ethereum game, generates a random value with publicly readable variables such as timestamp, the current block's blockhash, and a private variable (which can be read with a getStorageAt call). Therefore, attackers can precompute the random number and manipulate the game (e.g., get powerful characters or get critical damages).
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.