Crypto gaming platform PlayDapp suffered a catastrophic private key compromise that spawned 1.8 billion PLA tokens across two separate unauthorized minting events in February 2024, crushing the token's liquidity and forcing emergency protocol shutdowns.
On Feb. 9, an attacker minted 200 million PLA tokens valued at $36.5 million. PlayDapp immediately moved to contain the damage, offering the exploiter $1 million as a white hat bounty with a Feb. 13 deadline for asset return.
The offer failed. On Feb. 12, the exploiter minted 1.59 billion additional PLA tokens valued at $253.9 million—nearly tripling the platform's entire circulating supply of 577 million tokens that existed before the breaches. The move effectively torpedoed any realistic exit liquidity; dumping 1.8 billion tokens onto exchanges would crater the token price far below the initial theft value.
On-chain monitoring shows the attacker is liquidating anyway. Wallets tied to the exploiter have begun routing PLA to Gate and other exchanges in tranches. Elliptic, the blockchain forensics firm, has blacklisted the associated addresses across its AML tools, signaling exchanges to flag or block incoming deposits.
PlayDapp halted its smart contracts and announced a snapshot for asset migration to prevent further minting. PLA traded at $0.15 as of Feb. 13, down 2.9 percent in 24 hours—a muted reaction given the token supply dilution, suggesting holders are pricing in dilution and waiting for clarity on the recovery plan.
The incident underscores a persistent vulnerability in gaming protocols: centralized key management. PlayDapp's minting authority was not properly segregated or time-locked, allowing a single compromised key to inflate the supply at will. Axie Infinity ($620 million Ronin Bridge hack, 2022) and Vulcan Forged ($140 million, 2021) fell to similar architectural failures.