Stars Arena disclosed a major smart-contract breach on October 7, 2023, after an address extracted approximately 266,103 AVAX from the Avalanche-based social-finance application. CertiK valued the transferred tokens at approximately $2.88 million at the time of the incident, while contemporaneous reporting produced estimates between $2.85 million and $2.9 million as AVAX traded continuously.
The project’s official X account warned users not to deposit additional funds while its team investigated. The warning established that Stars Arena recognized an attack against its application contract; it did not identify a failure of the Avalanche consensus network or establish who controlled the receiving address.
What the transaction showed
Avalanche C-Chain transaction 0x4f37ffecdad598f53b8d5a2d9df98e3c00fbda4328585eb9947a412b5fe17ac5 is the central primary record. CertiK’s reconstruction found that the externally owned address beginning 0xa2Eb deposited 1 AVAX into the Stars Arena shares proxy and received approximately 266,103 AVAX from the contract during the same transaction sequence.
PeckShield and CertiK attributed the extraction to reentrancy. In that class of failure, a contract transfers value or invokes external code before completing all required internal state changes. The recipient can call back into the contract while the first operation remains unfinished, potentially causing calculations to use manipulated or inconsistent state.
CertiK reported that the address re-entered Stars Arena’s contract, changed a variable used as a weighted multiplier and then invoked the share-selling function. The resulting calculation authorized an abnormally large AVAX payment. That explanation was based on transaction flow and decompiled bytecode because the vulnerable implementation was not verified publicly, an important limitation on claims about the precise code path.
A fast-growing application met adversarial risk
Stars Arena had launched in late September as an Avalanche-based variation on Friend.tech’s social-token model. Users bought and sold profile-linked “tickets” denominated in AVAX, with ticket ownership providing access to private chats. Trading activity and the associated AVAX were therefore concentrated in application contracts whose accounting rules became economically significant within days.
The October 7 extraction followed a smaller vulnerability reported on October 5. Stars Arena said that earlier defect had been fixed, but the second incident showed that repairing one exploitable path did not demonstrate that the broader contract system was secure. Rapid adoption increased both the value available to attackers and the cost of incomplete testing.
Contemporaneous reporting distinguished AVAX held in users’ in-application wallets from value locked in the exploited shares contract. The Block reported that wallet withdrawals remained possible, while tickets tied to the emptied contract lacked realizable contract value. That distinction depended on Stars Arena’s architecture and should not be read as proof that every user balance or withdrawal succeeded.
What remained uncertain on October 7
The transaction established that AVAX left the contract, but it did not by itself establish the exploiter’s identity, intent or legal status. Stars Arena also reported a distributed-denial-of-service attack and said it was seeking a recovery solution. Those were contemporaneous company claims; no completed audit, reimbursement or binding recovery agreement was available on October 7.
The incident’s broader significance was architectural. A consumer application could generate substantial activity on a public blockchain while retaining application-level risks associated with unverified contracts, mutable assumptions and limited security review. Avalanche continued processing the transaction as designed; the failure described by investigators concerned Stars Arena’s contract logic.
Later context
On October 11, Stars Arena said approximately 90% of the extracted assets had been returned under an agreement allowing the responsible party a 10% bounty plus 1,000 AVAX reportedly lost during bridging. That subsequent recovery was not knowable on October 7 and does not change the event-day fact that the shares contract had been drained.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

