CVE-2018-13178: Ecpoints Project Ecpoints

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

The mintToken function of a smart contract implementation for ECToints (ECT) (Contract Name: ECPoints), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

Affected products

Published 2018-07-05. Last modified 2026-06-17.