Bitcoin Forum
February 26, 2026, 10:13:20 PM *
News: Latest Bitcoin Core release: 30.2 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Hack Our Smart Contract - Keep the $500,000 Prize | The Foom Heist  (Read 55 times)
mojefejkowe (OP)
Newbie
*
Offline Offline

Activity: 1
Merit: 0


View Profile
June 27, 2025, 07:07:07 PM
 #1

The Foom Heist Challenge is LIVE
Hack Our Protocol. Keep the $500,000 Prize.



Hello Bitcointalk,

We're Foom. We're building a decentralized, anonymous lottery protocol using ZK-proofs. We believe our code is secure, but we'd rather have it battle-tested by this community than assume we're right.

So, we're putting our money where our mouth is. We have funded a live smart contract on the Base L2 network with ~$500,000 worth of our $FOOM token.

The challenge is simple: If you can find an exploit and drain the contract, the funds are yours.

This isn't a theoretical bounty. It's a real, liquid, and verifiable prize.

The Prize & Liquidity
We know the first question is about the prize's real-world value. Let's be transparent.

  • The Prize: ~$500,000 in $FOOM tokens.
  • Proof of Value: We maintain a $5,000,000+ USD liquidity pool on Ethereum Mainnet. You can verify the health of the pool yourself on DEXTools.
  • Cashing Out: The $FOOM token is fully bridgeable from Base to Mainnet. The path is simple: Hack the contract on Base, bridge the tokens to ETH, and swap them.
Rules of Engagement
THE ONLY RULE IS THE CODE.

There are no sign-ups. No KYC. No "responsible disclosure" bureaucracy. If your code can take the funds, you've won. Our only request is a post-mortem disclosure of the method after you've secured the prize.

Technical Details & Resources
Everything you need is public. Do your own research.

Code:
0xdb203504ba1fea79164af3ceffba88c59ee8aafd
We'll be monitoring this thread for any technical questions.

Good luck.
haophd
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
Today at 09:05:30 AM
 #2

Hi, I did it. Where could I send the report?
haophd
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
Today at 12:06:32 PM
 #3

BTW, I'd like to thank DK27ss! This is an excellent analysis: https://github.com/DK27ss/FoomClub-1.6M-PoC . I don’t think any further explanation is needed, as it’s already clear.
henry_of_skalitz
Jr. Member
*
Offline Offline

Activity: 336
Merit: 8


View Profile
Today at 12:30:56 PM
 #4

You are two newbie accounts and haophd seemingly resolved the heist Smiley Do you have the address to which you sent the funds, haophd?
haophd
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
Today at 12:37:01 PM
 #5

Hi henry_of_skalitz,

The funds have been swapped to ETH and are currently held at this address: https://etherscan.io/address/haophd.eth.

People still believe this was a malicious exploit on social medias, so I hope there will be a correction to help protect the protocol’s reputation Smiley
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!