CVE-2018-13877: Megacryptopolis
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
The doPayouts() function of the smart contract implementation for MegaCryptoPolis, an Ethereum game, has a Denial of Service vulnerability. If a smart contract that has a fallback function always causing exceptions buys a land, users cannot buy lands near that contract's land, because those purchase attempts will not be completed unless the doPayouts() function successfully sends Ether to certain neighbors.
Affected products
- Megacryptopolis Megacryptopolis: affected versions not specified
Published 2018-08-06. Last modified 2026-06-17.