CVE-2018-10299

HIGH EXPLOITED IN THE WILD

Beauty Ecosystem Coin - Code Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2018-10299 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 1 public exploit from researchers including phzietsman.

AI-analyzed exploit summary This repository demonstrates and tests the batchOverflow vulnerability (CVE-2018-10299) in ERC20 smart contracts, including a vulnerable contract and a fixed version. The PoC uses Truffle tests to show how an integer overflow can be exploited to manipulate token balances.

Description

An integer overflow in the batchTransfer function of a smart contract implementation for Beauty Ecosystem Coin (BEC), the Ethereum ERC20 token used in the Beauty Chain economic system, allows attackers to accomplish an unauthorized increase of digital assets by providing two _receivers arguments in conjunction with a large _value argument, as exploited in the wild in April 2018, aka the "batchOverflow" issue.

Exploits (1)

nomisec WORKING POC
by phzietsman · remote
https://github.com/phzietsman/batchOverflow

This repository demonstrates and tests the batchOverflow vulnerability (CVE-2018-10299) in ERC20 smart contracts, including a vulnerable contract and a fixed version. The PoC uses Truffle tests to show how an integer overflow can be exploited to manipulate token balances.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: ERC20 smart contracts with batch transfer functionality
No auth needed
Prerequisites: Ethereum development environment (Truffle) · Vulnerable ERC20 smart contract
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory x_refsource_misc
https://twitter.com/OKEx_/status/987967343983714304
Issue Tracking, Third Party Advisory x_refsource_misc
https://www.reddit.com/r/ethereum/comments/8esyg9/okex_erc20_bug/
Exploit, Third Party Advisory x_refsource_misc
https://dasp.co/#item-3
Exploit, Third Party Advisory x_refsource_misc
https://peckshield.com/2018/04/22/batchOverflow/

Scores

CVSS v3 7.5
EPSS 0.0278
EPSS Percentile 84.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

VulnCheck KEV 2018-04-23
InTheWild.io 2018-08-29
CWE
CWE-190
Status published
Products (1)
beauty/beauty_ecosystem_coin
Published Apr 23, 2018
Tracked Since Feb 18, 2026