CVE-2018-13529
Description
The mintToken function of a smart contract implementation for BetterThanAdrien, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Integer overflow in BetterThanAdrien token's mintToken allows owner to set arbitrary user balances, enabling supply manipulation.
Vulnerability
The mintToken function in the BetterThanAdrien smart contract (an Ethereum token) contains an integer overflow vulnerability. This allows the contract owner to arbitrarily set the balance of any user by passing an overly large value that overflows the internal balance storage. The vulnerability affects all versions of the contract as described in the references [1], [2].
Exploitation
The attacker must be the owner of the contract. The owner calls mintToken with a target address and a value chosen to cause an integer overflow. Underflow or overflow of the user's balance results in the balance being set to an unexpected value (e.g., zero or a very large number), effectively giving the owner control over any account's token balance [1], [2].
Impact
Successful exploitation allows the contract owner to manipulate the token supply and set arbitrary balances for any user. This can lead to financial theft, denial of service (e.g., zeroing out user balances), or other malicious outcomes depending on the token's use [1], [2].
Mitigation
No official fix or patched version has been released. As a workaround, token holders may consider renaming or migrating to a contract that uses safe math libraries (e.g., OpenZeppelin's SafeMath) to prevent integer overflows. The contract may be presumed unmaintained or vulnerable [1], [2].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/BlockChainsSecurity/EtherTokens/blob/master/GEMCHAIN/mint%20integer%20overflow.mdmitrex_refsource_MISC
- github.com/BlockChainsSecurity/EtherTokens/tree/master/BetterThanAdrienmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.