<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Sorra_Contract_Flawed_Reward_Logic_Exploited</id>
	<title>Sorra Contract Flawed Reward Logic Exploited - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Sorra_Contract_Flawed_Reward_Logic_Exploited"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Sorra_Contract_Flawed_Reward_Logic_Exploited&amp;action=history"/>
	<updated>2026-05-30T07:49:44Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Sorra_Contract_Flawed_Reward_Logic_Exploited&amp;diff=6529&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/sorracontractflawedrewardlogicexploited.php}} {{Unattributed Sources}}  Sorra.io Logo/Homepage&lt;ref name=&quot;etherscan-17910&quot; /&gt;&lt;ref name=&quot;coingecko-17911&quot; /&gt;&lt;ref name=&quot;sorraarchive-17912&quot; /&gt;&lt;ref name=&quot;sorraarchive-17913&quot; /&gt;&lt;ref name=&quot;sorraarchive-17914&quot; /&gt;&lt;ref name=&quot;sorra-17915&quot; /&gt;&lt;ref name=&quot;coincheckup-17916&quot; /&gt;&lt;ref name=&quot;coingecko-17917&quot; /&gt;&lt;ref name=&quot;coinmonksme...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Sorra_Contract_Flawed_Reward_Logic_Exploited&amp;diff=6529&amp;oldid=prev"/>
		<updated>2025-02-07T23:32:43Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/sorracontractflawedrewardlogicexploited.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Sorraio.jpg&quot; title=&quot;File:Sorraio.jpg&quot;&gt;thumb|Sorra.io Logo/Homepage&lt;/a&gt;&amp;lt;ref name=&amp;quot;etherscan-17910&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;coingecko-17911&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;sorraarchive-17912&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;sorraarchive-17913&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;sorraarchive-17914&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;sorra-17915&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;coincheckup-17916&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;coingecko-17917&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;coinmonksme...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/sorracontractflawedrewardlogicexploited.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Sorraio.jpg|thumb|Sorra.io Logo/Homepage]]&amp;lt;ref name=&amp;quot;etherscan-17910&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;coingecko-17911&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;sorraarchive-17912&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;sorraarchive-17913&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;sorraarchive-17914&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;sorra-17915&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;coincheckup-17916&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;coingecko-17917&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;coinmonksmedium-17918&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;panewslab-17919&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;quillaudits-17920&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;theblock-17921&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;lunaraymedium-17922&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;sorraiotwitter-17923&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;tenarmoralerttwitter-17924&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;tikkalaresearchtwitter-17925&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;orbler1twitter-17926&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;coincreateteamtwitter-17927&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;kukayalabstwitter-17928&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;kukayalabstwitter-17929&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;ellioticianisttwitter-17930&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;kukayalabstwitter-17931&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;tomtalkofficialtwitter-17932&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;tryringaitwitter-17933&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;maaziemekatwitter-17934&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;marko369twitter-17935&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;ellioticianisttwitter-17936&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;alesandrod1sttwitter-17937&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About Sorra ==&lt;br /&gt;
Sorra is a decentralized platform transforming the future of hospitality and real estate investment. It offers a seamless ecosystem for both travelers and hosts, allowing property owners to earn rewards by listing properties, while guests benefit from affordable stays and earn $SOR tokens. Sorra features smart contracts to automate rental agreements, bookings, and payouts, and hosts can stake $SOR for passive income. The platform also introduces Sorra Estates, enabling fractional real estate ownership through tokenization. With plans for further expansion, Sorra aims to revolutionize short-term rentals and property investment.&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
The getPendingRewards() function in the Sorra smart contract failed to track and deduct previously distributed rewards, enabling repeated withdrawals of the same rewards.&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
&amp;quot;Sorra was suspected to have been attacked on ETH, resulting in an approximate loss of $43K.&amp;quot;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - Sorra Contract Flawed Reward Logic Exploited&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|January 4th, 2025 4:59:23 AM MST&lt;br /&gt;
|Sorra Contract Exploited&lt;br /&gt;
|The Sorra smart contract is exploited.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
The getPendingRewards() function in the Sorra smart contract failed to track and deduct previously distributed rewards, enabling repeated withdrawals of the same rewards.&lt;br /&gt;
&lt;br /&gt;
This issue prevented the contract from properly tracking and deducting previously distributed rewards, allowing the attacker to repeatedly withdraw the same rewards. The attacker, who had deposited 122,868 SOR tokens on December 21, 2024, took advantage of this flaw, draining a total of 3,071,721 SOR tokens and making an approximate profit of $41,000.&lt;br /&gt;
&lt;br /&gt;
The exploit unfolded when the attacker, after the 14-day lockup period, initiated the withdraw() function on January 4, 2025. This function was designed to handle the withdrawal of staked tokens along with any pending rewards. However, due to the flaw, the system did not update the rewards balance correctly, enabling the attacker to call the withdraw() function multiple times with minimal token amounts. As a result, the attacker managed to drain the tokens and convert them into profits.&lt;br /&gt;
&lt;br /&gt;
The root cause of this exploit was the failure of the getPendingRewards() function to account for the userRewardsDistributed[_msgSender()] value. This oversight allowed rewards to be double-counted and withdrawn multiple times.&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
Loss estimates have ranged between $41k and 43k.&lt;br /&gt;
&lt;br /&gt;
The total amount lost has been estimated at $43,000 USD.&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed?&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
Sorra appears to have deleted their website and social media following the exploit.&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
There do not appear to have been any funds recovered in this case.&lt;br /&gt;
&lt;br /&gt;
What funds were recovered? What funds were reimbursed for those affected users?&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
What parts of this case are still remaining to be concluded?&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;etherscan-17910&amp;quot;&amp;gt;[https://etherscan.io/tx/0x6439d63cc57fb68a32ea8ffd8f02496e8abad67292be94904c0b47a4d14ce90d Ethereum Transaction Hash (Txhash) Details | Etherscan] (Accessed Feb 7, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;coingecko-17911&amp;quot;&amp;gt;[https://www.coingecko.com/en/coins/sorra https://www.coingecko.com/en/coins/sorra] (Accessed Feb 7, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;sorraarchive-17912&amp;quot;&amp;gt;[https://web.archive.org/web/20240723104041/https://www.sorra.io/ Sorra] (Accessed Feb 7, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;sorraarchive-17913&amp;quot;&amp;gt;[https://web.archive.org/web/20240909144332/https://www.sorra.io/ Sorra] (Accessed Feb 7, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;sorraarchive-17914&amp;quot;&amp;gt;[https://web.archive.org/web/20241115140755/https://www.sorra.io/ Sorra] (Accessed Feb 7, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;sorra-17915&amp;quot;&amp;gt;[https://www.sorra.io/lander https://www.sorra.io/lander] (Accessed Feb 7, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;coincheckup-17916&amp;quot;&amp;gt;[https://coincheckup.com/coins/sorra/about Cryptocurrency Prices, Charts &amp;amp; Crypto Market Cap - CoinCheckup] (Accessed Feb 7, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;coingecko-17917&amp;quot;&amp;gt;[https://www.coingecko.com/en/coins/sorra/usd https://www.coingecko.com/en/coins/sorra/usd] (Accessed Feb 7, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;coinmonksmedium-17918&amp;quot;&amp;gt;[https://medium.com/coinmonks/sorra-finance-staking-exploit-41-000-drained-in-flawed-reward-logic-3771a6efb019 Sorra Finance Staking Exploit 41 000 Drained In Flawed Reward Logic] (Accessed Feb 7, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;panewslab-17919&amp;quot;&amp;gt;[https://www.panewslab.com/en/articledetails/li2cs123jh5h.html Cryptocurrency Monthly Report: In January, the security loss of funds was about 98 million US dollars, a significant decrease both year-on-year and month-on-month - PANews] (Accessed Feb 7, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;quillaudits-17920&amp;quot;&amp;gt;[https://www.quillaudits.com/web3-hacks-database Web3 Hacks Database: Major Hacks &amp;amp; Scams Analyzed] (Accessed Feb 7, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;theblock-17921&amp;quot;&amp;gt;[https://www.theblock.co/post/337976/january-2025-crypto-hacks https://www.theblock.co/post/337976/january-2025-crypto-hacks] (Accessed Feb 7, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;lunaraymedium-17922&amp;quot;&amp;gt;[https://lunaray.medium.com/sorrastaking-hack-analysis-60e8cd9ca026 Sorrastaking Hack Analysis] (Accessed Feb 7, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;sorraiotwitter-17923&amp;quot;&amp;gt;[https://twitter.com/sorra_io @sorra_io Twitter] (Accessed Feb 7, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;tenarmoralerttwitter-17924&amp;quot;&amp;gt;[https://twitter.com/TenArmorAlert/status/1875582709512188394 @TenArmorAlert Twitter] (Accessed Feb 7, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;tikkalaresearchtwitter-17925&amp;quot;&amp;gt;[https://twitter.com/TikkalaResearch/status/1876344921235529815 @TikkalaResearch Twitter] (Accessed Feb 7, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;orbler1twitter-17926&amp;quot;&amp;gt;[https://twitter.com/Orbler1/status/1871473786366939364 @Orbler1 Twitter] (Accessed Feb 7, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;coincreateteamtwitter-17927&amp;quot;&amp;gt;[https://twitter.com/CoincreateTeam/status/1875573059681447992 @CoincreateTeam Twitter] (Accessed Feb 7, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;kukayalabstwitter-17928&amp;quot;&amp;gt;[https://twitter.com/KukayaLabs/status/1871494982298673203 @KukayaLabs Twitter] (Accessed Feb 7, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;kukayalabstwitter-17929&amp;quot;&amp;gt;[https://twitter.com/KukayaLabs/status/1875303690300784732 @KukayaLabs Twitter] (Accessed Feb 7, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;ellioticianisttwitter-17930&amp;quot;&amp;gt;[https://twitter.com/Ellioticianist/status/1874569790171562196 @Ellioticianist Twitter] (Accessed Feb 7, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;kukayalabstwitter-17931&amp;quot;&amp;gt;[https://twitter.com/KukayaLabs/status/1871286649914536271 @KukayaLabs Twitter] (Accessed Feb 7, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;tomtalkofficialtwitter-17932&amp;quot;&amp;gt;[https://twitter.com/Tomtalkofficial/status/1873738169528816011 @Tomtalkofficial Twitter] (Accessed Feb 7, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;tryringaitwitter-17933&amp;quot;&amp;gt;[https://twitter.com/TryRingAI/status/1875589221752164797 @TryRingAI Twitter] (Accessed Feb 7, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;maaziemekatwitter-17934&amp;quot;&amp;gt;[https://twitter.com/Maaziemeka/status/1874917520551063822 @Maaziemeka Twitter] (Accessed Feb 7, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;marko369twitter-17935&amp;quot;&amp;gt;[https://twitter.com/Mar_Ko369/status/1872645749215043944 @Mar_Ko369 Twitter] (Accessed Feb 7, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;ellioticianisttwitter-17936&amp;quot;&amp;gt;[https://twitter.com/Ellioticianist/status/1873108175584673857 @Ellioticianist Twitter] (Accessed Feb 7, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;alesandrod1sttwitter-17937&amp;quot;&amp;gt;[https://twitter.com/_AlesandroD1st/status/1873781690381877553 @_AlesandroD1st Twitter] (Accessed Feb 7, 2025)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>