QI Quadriga Initiative

Jan 2025 - Sorra Contract Flawed Reward Logic Exploited - $43k (Global)

Sorra is a decentralized platform transforming the future of hospitality and real estate investment. It offers a seamless ecosystem for both travelers and hosts, allowing property owners to earn rewards by listing properties, while guests benefit from affordable stays and earn $SOR tokens. Sorra features smart contracts to automate rental agreements, bookings, and payouts, and hosts can stake $SOR for passive income. The platform also introduces Sorra Estates, enabling fractional real estate ownership through tokenization. With plans for further expansion, Sorra aims to revolutionize short-term rentals and property investment.

The getPendingRewards() function in the Sorra smart contract failed to track and deduct previously distributed rewards, enabling repeated withdrawals of the same rewards.

The getPendingRewards() function in the Sorra smart contract failed to track and deduct previously distributed rewards, enabling repeated withdrawals of the same rewards.

This issue prevented the contract from properly tracking and deducting previously distributed rewards, allowing the attacker to repeatedly withdraw the same rewards. The attacker, who had deposited 122,868 SOR tokens on December 21, 2024, took advantage of this flaw, draining a total of 3,071,721 SOR tokens and making an approximate profit of $41,000.

The exploit unfolded when the attacker, after the 14-day lockup period, initiated the withdraw() function on January 4, 2025. This function was designed to handle the withdrawal of staked tokens along with any pending rewards. However, due to the flaw, the system did not update the rewards balance correctly, enabling the attacker to call the withdraw() function multiple times with minimal token amounts. As a result, the attacker managed to drain the tokens and convert them into profits.

The root cause of this exploit was the failure of the getPendingRewards() function to account for the userRewardsDistributed[_msgSender()] value. This oversight allowed rewards to be double-counted and withdrawn multiple times.

Loss estimates have ranged between $41k and 43k.

Sorra appears to have deleted their website and social media following the exploit.

Further Analysis

More Cryptocurrency Exchange Hacks/Scams/Frauds

Solv Protocol New Token Twitter/X Account Phishing > > < < Babylon Labs Phishing Twitter/X Account Compromise

Sources/Further Reading

Ethereum Transaction Hash (Txhash) Details | Etherscan (Dec 31)
https://www.coingecko.com/en/coins/sorra (Dec 31)
Sorra (Dec 31)
Sorra (Dec 31)
Sorra (Dec 31)
https://www.sorra.io/lander (Dec 31)
Cryptocurrency Prices, Charts & Crypto Market Cap - CoinCheckup (Dec 31)
https://www.coingecko.com/en/coins/sorra/usd (Dec 31)
Sorra Finance Staking Exploit 41 000 Drained In Flawed Reward Logic (Dec 31)
Cryptocurrency Monthly Report: In January, the security loss of funds was about 98 million US dollars, a significant decrease both year-on-year and month-on-month - PANews (Dec 31)
Web3 Hacks Database: Major Hacks & Scams Analyzed (Dec 31)
https://www.theblock.co/post/337976/january-2025-crypto-hacks (Dec 31)
Sorrastaking Hack Analysis (Dec 31)
@sorra_io Twitter (Dec 31)
@TenArmorAlert Twitter (Dec 31)
@TikkalaResearch Twitter (Dec 31)
@Orbler1 Twitter (Dec 31)
@CoincreateTeam Twitter (Dec 31)
@KukayaLabs Twitter (Dec 31)
@KukayaLabs Twitter (Dec 31)
@Ellioticianist Twitter (Dec 31)
@KukayaLabs Twitter (Dec 31)
@Tomtalkofficial Twitter (Dec 31)
@TryRingAI Twitter (Dec 31)
@Maaziemeka Twitter (Dec 31)
@Mar_Ko369 Twitter (Dec 31)
@Ellioticianist Twitter (Dec 31)
@_AlesandroD1st Twitter (Dec 31)


Join Us!

Name: Email:

t.me/QuadrigaInitiative /r/QuadrigaInitiative @QuadrigaInit info@quadrigainitiative.com

Sign-Ups: 100%

Your use of this site/service accepts the Terms of Use and Privacy Policy. This site is not associated with Ernst & Young, Miller Thompson, or the Official Committee of Affected User. For questions or enquiries, email info@quadrigainitiative.com.