⚠️ JUST IN: Telegram casino "Unbox" exploited for approximately $130,000 via race-condition vulnerability.
A vulnerability in the Telegram-based casino "Unbox", operated by well-known middleman @nine, was allegedly exploited to convert roughly $120 into nearly $130,000.
According to reports, the attacker automated two API requests against a mines-style game within the same millisecond. While a game round was still active, the attacker triggered a seed reset, because the previous seed had already been revealed before the round was finalized, the attacker was able to determine the outcome tied to the old seed and complete the game with effectively guaranteed winning bets. By repeatedly abusing the race-condition flaw, the attacker reportedly scaled their balance significantly.
After attempting to withdraw the funds, the account was reportedly blacklisted by the platform.
After their withdrawal was blocked, the exploiter publicly criticized the casino and suggested misconduct on its part. The individual later admitted that the funds had been obtained by exploiting a vulnerability in the platform, undermining claims that the incident constituted an exit scam.
We reached out to @nine about the exploit for comment but did not receive a response by publication time.
The incident highlights a broader issue facing many Telegram-based casinos and gambling applications. Security controls, game-state validation, concurrency protections, and backend auditing are often less mature than those found at larger regulated gaming platforms, making race conditions and logic flaws particularly dangerous when real funds are involved.
At the time of writing, there is no evidence that @unbox or it's operator, @nine, conducted an exit scam.
@arch
Post #32
1.99K

- ❤ 9