VYPR
Unrated severityNVD Advisory· Published Jul 9, 2018· Updated Aug 5, 2024

CVE-2018-13675

CVE-2018-13675

Description

Integer overflow in YAMBYO token's mintToken function lets the contract owner arbitrarily set any user's balance.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Integer overflow in YAMBYO token's mintToken function lets the contract owner arbitrarily set any user's balance.

Vulnerability

The mintToken function in the YAMBYO smart contract (Ethereum token) contains an integer overflow vulnerability [2]. The function does not properly check arithmetic operations, allowing the owner to mint an arbitrary number of tokens. This is a common pattern in vulnerable ERC-20 tokens [1]. The affected contract is the YAMBYO token implementation as found in the EtherTokens repository [2].

Exploitation

The attacker must be the contract owner (the address that deployed the contract). The owner calls mintToken with a target address and a large mintedAmount value that causes an integer overflow in the balance update. No user interaction or special network position is required beyond being the owner.

Impact

By exploiting the overflow, the owner can set the balance of any user to any value, effectively creating tokens out of thin air. This can lead to total loss of token value, manipulation of supply, and potential theft from other users if the inflated balance is used to transfer tokens.

Mitigation

No official fix has been published for this specific contract. The vulnerability is inherent in the code as deployed. Developers should use SafeMath libraries to prevent integer overflows [1]. Users should avoid interacting with the YAMBYO token until a patched version is released.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

0

No linked articles in our index yet.