A stolen key let PlayDapp's attacker mint 1.8 billion tokens
The Web3 gaming platform lost about $290 million in February 2024 after an intruder made themselves an authorized minter of the PLA token and printed coins at will, per Elliptic.
Most crypto thefts move coins that already exist. The PlayDapp attack manufactured them. In February 2024 the Web3 gaming platform lost roughly $290 million in PLA tokens — not by draining a wallet, but by seizing the power to create new ones, per Elliptic.
The flaw was in access control. Using what analysts describe as a compromised private key, the attacker called a function that "add[ed] themselves as an official minter on the project," Halborn wrote — handing an outsider the authority PlayDapp reserved for itself.
Two mints, four days apart
On Feb. 9 the attacker minted 200 million PLA, worth about $36.5 million at the time, per Elliptic. PlayDapp tried to negotiate, offering a $1 million white-hat reward for the tokens' return.
The offer failed. On Feb. 12 the attacker minted a further 1.59 billion PLA — around $253.9 million — bringing the total to roughly 1.8 billion new tokens, Halborn said. That printed supply dwarfed the roughly 577 million PLA already in circulation, per Elliptic.
Why the paper loss shrank
The flood was also the attacker's problem: dumping billions of freshly minted tokens crushed PLA's price, so the realized haul fell well short of the headline figure. PlayDapp paused the contract, coordinated with exchanges to freeze tokens, and snapshotted balances for a migration to a new token, per Halborn.
An unguarded mint function is among the most dangerous holes in any token contract. What it teaches:
- Minting and role-granting functions deserve the tightest controls — multisig or timelock, never a lone hot key.
- A leaked admin private key is not a theft of funds; it is a theft of the money printer.
- Headline 'loss' figures for inflation attacks overstate the payday — thin liquidity limits what a thief can cash out.
- Holders should know who can mint and how; if the answer is one key, the supply is one phishing email from infinite.
For players holding a game's token, PlayDapp is a reminder that the asset's scarcity is a promise kept in code — and only as trustworthy as the keys that guard it.
— Sources: [Elliptic](https://www.elliptic.co/blog/crypto-gaming-platform-playdapp-suffers-290-million-breach) · [Halborn](https://www.halborn.com/blog/post/explained-the-playdapp-hack-february-2024)
NOT FINANCIAL ADVICE · VERIFY EVERYTHING