vciy

The mintToken function of a smart contract implementation: 315 records in one advisory

315 records announced together, published between 2018-07-05 and 2018-07-09, every one of them citing the same advisory.

The advisory

Every record in this batch cites https://github.com/BlockChainsSecurity/EtherTokens/blob/master/GEMCHAIN/mint%20integer%20overflo…. That is the CNA's own reference, held in the index, and it is why these records are on one page.

What the records offer

No record in this batch publishes a fixed version in held sources.

No record in this batch is listed by CISA in held sources.

Every record names something of its own, listed against it below.

What this page does not cover

This batch is 315 of the 363 records that cite the same advisory. The other 48 are different findings announced alongside it.

None of those 48 is grouped with any other. Each one has its own record page and nothing else.

The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.

What this batch was researched, not held

One lab's catalogue of copied token code, filed as one record per contract address

The anchor is a single markdown file in the GitHub repository BlockChainsSecurity/EtherTokens, created on 3 July 2018, whose repository description reads "Credit by ADLab of Venustech", the research lab of the Chinese security company Venustech. The file takes one Ethereum token, GEMCHAIN, as its worked example. It shows the unguarded mintToken function, walks a proof of concept through the Remix development tool, and shows the owner setting an arbitrary user's balance to zero by overflowing it. Then it says: "Other tokens found vulnerable by us are listed below. These ones have a similar code pattern." What follows is 370 further token sections, each with its own contract address on Etherscan and its own copy of the code, 366 distinct addresses in all. The identifiers came out in two bursts. Across the 2018 public CVE records, 401 cite this repository and 363 of those point at this one file. All 401 were assigned by MITRE, and they were published on exactly two days: 79 on 5 July 2018 and 322 on 9 July 2018. That is why they read identically apart from the token name.

Each record names one contract, deployed at one address, owned by one account. The other records catalogued in the same file name different contracts belonging to different owners. The report's own claim is that they carry a similar code pattern, which is a statement about the source code it prints, not about the contracts being one finding.

2018-07-03The BlockChainsSecurity/EtherTokens repository is created on GitHub.
2018-07-05The first 79 identifiers citing the repository are published, including CVE-2018-13155 for GEMCHAIN.
2018-07-09The remaining 322 are published on a single day.

A deployed contract cannot be patched at its address, and the file says nothing about whether any of these operators later redeployed or moved holders to a new contract, so nothing here tells you the state of any address now. The file also names no individual author, only the lab in the repository description, and carries no dates, no disclosure history and no vendor contact.

Written from raw.githubusercontent.com, github.com, api.github.com, services.nvd.nist.gov. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2018-13155gemchain gem
CVE-2018-13156bonustoken bns
CVE-2018-13157cryptonitexcoin
CVE-2018-13158assettoken
CVE-2018-13159bankcoin bnk
CVE-2018-13160etktokens etk
CVE-2018-13161multigames mlt
CVE-2018-13164eppcoin epp
CVE-2018-13165justdcoin justd
CVE-2018-13166athleticoin atha
CVE-2018-13171ladatoken ldt
CVE-2018-13172bzxcoin bzx
CVE-2018-13173eliteshippertoken eship
CVE-2018-13174cryptoabs abs
CVE-2018-13182loncoin lon
CVE-2018-13185appcoins appc
CVE-2018-13186mmtcoin mmt
CVE-2018-13192jobscoin job
CVE-2018-13193hentaisolo hao
CVE-2018-13195cranoo crn
CVE-2018-13463t-swap-token t-s-t
CVE-2018-13467epiphanycoin
CVE-2018-13469icocontract
CVE-2018-13470buyertoken
CVE-2018-13471beyondcashtoken
CVE-2018-13473ohni_2 ohni
CVE-2018-13474fanschaintoken
CVE-2018-13479slidebitstoken
CVE-2018-13482ethercash etc
CVE-2018-13483mkethtoken
CVE-2018-13485bitcoinagiletoken
CVE-2018-13487platotoken
CVE-2018-13493daddytoken
CVE-2018-13494susantokenerc20
CVE-2018-13496rajtestico
CVE-2018-13500msxadvanced
CVE-2018-13502heliumnetwork
CVE-2018-13505ecogreenhouse
CVE-2018-13507slcadvancedtoken
CVE-2018-13511corellicoin
CVE-2018-13512smarthomecoin
CVE-2018-13520topscoinadvanced
CVE-2018-13521pinkytoken
CVE-2018-13523smartpayment
CVE-2018-13524porncoin prnc
CVE-2018-13526wangwangtoken
CVE-2018-13527elevatecoin
CVE-2018-13529betterthanadrien
CVE-2018-13530huntercoin
CVE-2018-13532mindexcoin
CVE-2018-13534speedcashlite scsl
CVE-2018-13537ethereumlegit
CVE-2018-13543gemstonetoken
CVE-2018-13545hashshield
CVE-2018-13549neurotoken
CVE-2018-13552trabet_coin_preico
CVE-2018-13553micro btc mbtc
CVE-2018-13554moneytree tree
CVE-2018-13556cosmotokenerc20
CVE-2018-13557trabet_coin
CVE-2018-13560kelvintoken
CVE-2018-13574datashieldcoin
CVE-2018-13578galaxycoin
CVE-2018-13579forevercoin
CVE-2018-13581travelcoin trv
CVE-2018-13585cherrycoin
CVE-2018-13586nectar nctr
CVE-2018-13589mooadvtoken
CVE-2018-13594cardfactory
CVE-2018-13599residualvalue
CVE-2018-13603briant2token
CVE-2018-13607residualshare
CVE-2018-13608archercoin
CVE-2018-13610medicayunlink
CVE-2018-13611cdcurrency
CVE-2018-13618vicetoken_ico_is_a_scam
CVE-2018-13619micointoken
CVE-2018-13621soundtribetoken
CVE-2018-13622objecttoken obj
CVE-2018-13623airdroppercryptics
CVE-2018-13626semaintoken
CVE-2018-13628momentumtoken
CVE-2018-13629crimsonshilling
CVE-2018-13630doccoinpreico
CVE-2018-13634mediacubetoken
CVE-2018-13640ethereumsmart
CVE-2018-13643gcrtokenerc20
CVE-2018-13644royalclassiccoin
CVE-2018-13647truegoldcointoken
CVE-2018-13650bitmaxertoken
CVE-2018-13651micoinnetworktoken
CVE-2018-13652thegodigital
CVE-2018-13658thegodgital
CVE-2018-13662worldopctionchain
CVE-2018-13666eristicaico
CVE-2018-13667utbtokentest
CVE-2018-13671dinsteincoin
CVE-2018-13673goldtokenerc20
CVE-2018-13674combilladvancedtoken
CVE-2018-13680lexittoken
CVE-2018-13682vitemoneycoin
CVE-2018-13687normikaivo
CVE-2018-13690instacocoa
CVE-2018-13692mehditazitoken
CVE-2018-13693greenenergytoken
CVE-2018-13699destineed dsn
CVE-2018-13717hormitechtoken
CVE-2018-13719bitedutoken
CVE-2018-13721gomineworld
CVE-2018-13723servviziotoken
CVE-2018-13725globalsupergametoken
CVE-2018-13726iseevoicetoken
CVE-2018-13731tokenmachu
CVE-2018-13732riptidecoin ript
CVE-2018-13736elearningcoinerc
CVE-2018-13738pelocointoken
CVE-2018-13739dopnetwork
CVE-2018-13741ablgenesistoken
CVE-2018-13742tickets tkt
CVE-2018-13743superenergy sec
CVE-2018-13744crowdnext cnx
CVE-2018-13747vanminhcoin
CVE-2018-13749finaltoken
CVE-2018-13750richiumtoken
CVE-2018-13751justwallet
CVE-2018-13753deweisecurityservicetoken
CVE-2018-13754cryptosistoken
CVE-2018-13755otakutoken
CVE-2018-13756cherrycoinfoundation
CVE-2018-13759bigcadvancedtoken
CVE-2018-13760moneychainnet mcn
CVE-2018-13761netkilleradvancedtokenairdrop
CVE-2018-13767cornerstone
CVE-2018-13769jeanstoken
CVE-2018-13770ultimatecoin
CVE-2018-13771exacorecontract
CVE-2018-13772theflashtoken
CVE-2018-13776appletoken
CVE-2018-13783jiucaitoken

315 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.