{"investigation":{"slug":"gmblcomputer","entity_name":"GMBL.COMPUTER","trust_score":38,"severity_base":null,"score_modifier":0,"confidence":0.72,"status":"published","content_type":"investigation","summary":"GMBL.COMPUTER is an Arbitrum-based DeFi gambling protocol that launched in September 2023 and was exploited within hours of going live, losing approximately 471 ETH (~$770,000) due to an off-chain server signature vulnerability and a flaw in its referral system. The exploiter returned roughly half of the stolen funds (235 ETH) after the team issued a conditional bug bounty offer. The protocol operates with an anonymous team, no disclosed security audits, no regulatory licensing, and as of 2025 shows near-zero trading volume and minimal on-chain activity.","sections":[{"content":"GMBL.COMPUTER describes itself as an 'Omnichain DeFi protocol' and 'People's Casino' built on the Arbitrum network. The platform offers on-chain casino games (crash, planned plinko, mines, dice) and sports betting, with the stated model of routing 100% of house profits to holders of xGMBL, the non-transferable staked version of the GMBL token. Users can also provide liquidity to earn fees, and a referral program offers 5% of all referral losses in perpetuity. The platform distinguishes itself legally by claiming to be 'a software company, not an online casino,' with core contributors stating they do not stake or profit directly from player losses. GMBL tokens were launched via a Liquidity Bootstrapping Pool (LBP) on the Camelot Exchange launchpad on Arbitrum. Total token supply is 100 million GMBL. The project raised approximately $100,000 in public and private rounds at launch. The protocol is deployed on Arbitrum One; the primary token contract address is 0xE9A5aF50874c0ef2748b5DB70104B5ccb5557f6d on Arbitrum.","heading":"Protocol Overview","sources":[{"url":"https://gmblcomputer.gitbook.io/gmbl.computer","name":"gmblcomputer.gitbook.io","type":"other","credibility":3},{"url":"https://coinmarketcap.com/currencies/gmbl-computer/","name":"coinmarketcap.com","type":"other","credibility":3},{"url":"https://arbiscan.io/token/0xE9A5aF50874c0ef2748b5DB70104B5ccb5557f6d","name":"arbiscan.io","type":"other","credibility":3},{"url":"https://cryptorank.io/ico/gmbl-computer","name":"cryptorank.io","type":"other","credibility":3}],"severity":"medium"},{"content":"GMBL.COMPUTER was exploited on September 5-6, 2023, within approximately 24 hours of its official mainnet launch. The exploit resulted in the loss of approximately 471 ETH, valued at roughly $770,000 at the time. The team characterized the root cause as 'off-chain' rather than a smart contract vulnerability. According to the team's postmortem, an attacker was able to spoof a call to obtain a valid signature from GMBL's server, which was then passed to the on-chain contract to withdraw GMBL tokens worth nearly 500 ETH from the protocol. A secondary attack vector involved the referral system: the attacker placed 'ghost' bets on the crash game by passing parameters directly to the route without depositing funds. These ghost bets were registered as losses in the ledger, enabling the attacker's referral accounts to claim 5% commissions on fabricated losses. The team's postmortem described the flaw as 'embarrassingly simple' and 'a one-line fix.' Approximately 8 million GMBL tokens were claimed via this referral abuse before the exploit was halted. In the aftermath, the GMBL token price dropped approximately 75%. The team suspended all contract interactions immediately upon discovery.","heading":"September 2023 Exploit: Off-Chain Signature Vulnerability","sources":[{"url":"https://gmblcomputer.medium.com/gmbl-computer-exploit-postmortem-a09aa3297405","name":"gmblcomputer.medium.com","type":"other","credibility":3},{"url":"https://beincrypto.com/defi-gmbl-computer-exploited-eth-funds-returned/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/single/gmblcomputer-exploit","name":"web3isgoinggreat.com","type":"other","credibility":3},{"url":"https://coincu.com/215747-gmblcomputer-key-leaked-loss-nearly-500-eth/","name":"coincu.com","type":"other","credibility":3},{"url":"https://slowmist.medium.com/slowmist-weekly-security-report-september-4rd-to-10th-3310d4258f48","name":"slowmist.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, the GMBL team publicly identified the attacker and issued a conditional bounty offer: return 90% of stolen funds (approximately 424 ETH) by 9 PM EST the following day, and the team would not pursue legal action, allowing the attacker to retain 10% (~47 ETH) as compensation. The team set a deadline and threatened legal action if the funds were not returned. The attacker ultimately returned 235 ETH, equivalent to approximately $382,000 and roughly half of the total stolen amount. The remaining approximately 236 ETH (~$388,000) was not recovered. The team stated it had 'found the exploiter' but public records do not confirm any law enforcement action or civil litigation resulting from the incident. The team expressed accountability in communications, stating 'We let you down,' and committed to delaying the platform relaunch pending enhanced security measures including third-party server code audits and referral system validation.","heading":"Fund Recovery and Bug Bounty Negotiation","sources":[{"url":"https://beincrypto.com/defi-gmbl-computer-exploited-eth-funds-returned/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/single/gmblcomputer-exploit","name":"web3isgoinggreat.com","type":"other","credibility":3},{"url":"https://gmblcomputer.medium.com/gmbl-computer-exploit-postmortem-a09aa3297405","name":"gmblcomputer.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The GMBL.COMPUTER team operates under pseudonymous or anonymous identities. The official GitBook documentation refers only to 'Core Contributors' without disclosing any names, professional backgrounds, or organizational details. No team members have been publicly identified in any news coverage or official communications reviewed for this investigation. The project's legal disclaimer asserts that 'Core Contributors do not profit from losses on the platform' and 'do not stake,' positioning them as infrastructure providers rather than casino operators. However, the absence of any named or verifiable team members limits accountability, particularly given that the September 2023 exploit stemmed from an off-chain server-side vulnerability — meaning the security of user funds relied on infrastructure controlled by unidentified parties. The platform's legal framing as 'a software company, not an online casino' appears designed to navigate regulatory scrutiny, though no formal legal opinions supporting this characterization have been publicly disclosed.","heading":"Team Anonymity and Transparency Concerns","sources":[{"url":"https://gmblcomputer.gitbook.io/gmbl.computer","name":"gmblcomputer.gitbook.io","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/single/gmblcomputer-exploit","name":"web3isgoinggreat.com","type":"other","credibility":3}],"severity":"medium"},{"content":"GMBL.COMPUTER holds no disclosed gambling licenses from any jurisdiction and has not registered with the SEC, CFTC, or any comparable financial or gaming regulator. The platform explicitly positions itself as a 'software company' rather than an online casino in its documentation, a framing intended to place it outside traditional gambling regulatory frameworks. No regulatory actions against GMBL.COMPUTER have been identified in public records as of the date of this investigation. The team's legal disclaimer states: 'GMBL Computer does not make any guarantees regarding any of its products.' The protocol operates in a legal gray area common to DeFi gambling platforms, with users in many jurisdictions potentially violating local gambling laws by using the platform. No jurisdiction-based access controls or KYC/AML procedures are disclosed in the project documentation.","heading":"Regulatory and Licensing Status","sources":[{"url":"https://gmblcomputer.gitbook.io/gmbl.computer","name":"gmblcomputer.gitbook.io","type":"other","credibility":3},{"url":"https://coinmarketcap.com/currencies/gmbl-computer/","name":"coinmarketcap.com","type":"other","credibility":3}],"severity":"medium"},{"content":"No third-party smart contract security audits for GMBL.COMPUTER have been identified in any public documentation, security firm report indexes, or official project communications reviewed for this investigation. The September 2023 exploit exposed both an off-chain server-side vulnerability (improper signature validation) and an on-chain logic flaw (referral system accepting unverified bet losses). The team's postmortem acknowledged the vulnerability was 'a one-line fix,' suggesting that a pre-launch security review would likely have identified the issue. Following the exploit, the team committed to engaging third-party auditors for server code and to implementing referral system checks before relaunch, but no audit reports have been publicly published. SlowMist documented the incident in their weekly security report as a notable exploit but did not publish a formal audit of GMBL.COMPUTER's codebase.","heading":"Security Posture and Audit History","sources":[{"url":"https://gmblcomputer.medium.com/gmbl-computer-exploit-postmortem-a09aa3297405","name":"gmblcomputer.medium.com","type":"other","credibility":3},{"url":"https://slowmist.medium.com/slowmist-weekly-security-report-september-4rd-to-10th-3310d4258f48","name":"slowmist.medium.com","type":"other","credibility":3},{"url":"https://gmblcomputer.gitbook.io/gmbl.computer","name":"gmblcomputer.gitbook.io","type":"other","credibility":3}],"severity":"medium"},{"content":"As of 2025, GMBL.COMPUTER shows near-zero trading volume across tracked exchanges. Market data aggregators including CoinBrain report approximately 19 token holders and a market capitalization of approximately $156,000, suggesting the protocol has experienced near-total collapse in user activity. The token's all-time high of approximately $0.171 was recorded on November 30, 2023, roughly three months after the exploit. The project's DEX listing on Camelot (Arbitrum) at 0x70eb6e93e1f8bfb850126e23a1964fd3db789948 shows negligible liquidity. No public updates from the GMBL team confirming a successful relaunch with the enhanced security measures promised post-exploit have been identified. The project's social media account (@gmblcomputer on X) remains accessible but activity levels have not been independently verified for this investigation.","heading":"Market Activity and Current Protocol Status","sources":[{"url":"https://coinmarketcap.com/currencies/gmbl-computer/","name":"coinmarketcap.com","type":"other","credibility":3},{"url":"https://dexscreener.com/arbitrum/0x70eb6e93e1f8bfb850126e23a1964fd3db789948","name":"dexscreener.com","type":"other","credibility":3},{"url":"https://www.coingecko.com/en/coins/gmbl-computer-chip","name":"coingecko.com","type":"other","credibility":3},{"url":"https://coinbrain.com/coins/eth-0xa395bd32dd0ac0823bf160cd6e0db2ac08d7cdcd","name":"coinbrain.com","type":"other","credibility":3}],"severity":"medium"},{"content":"GMBL.COMPUTER has been flagged in association with ZachXBT, the pseudonymous on-chain investigator known for exposing scams and protocol vulnerabilities in the crypto space. The specific nature and date of ZachXBT's flagging of GMBL.COMPUTER have not been independently verified through a directly attributable public post for this investigation. The September 2023 exploit was covered by Web3 Is Going Great, a tracker maintained by crypto skeptic Molly White that documents harmful incidents in the crypto space, and was included in SlowMist's weekly threat intelligence report. The exploit's occurrence hours after mainnet launch — combined with the off-chain server vulnerability, anonymous team, absence of audits, and partial fund recovery — presents a risk profile consistent with entities that receive attention from independent investigators in the crypto security community.","heading":"ZachXBT Association","sources":[{"url":"https://www.web3isgoinggreat.com/single/gmblcomputer-exploit","name":"web3isgoinggreat.com","type":"other","credibility":3},{"url":"https://slowmist.medium.com/slowmist-weekly-security-report-september-4rd-to-10th-3310d4258f48","name":"slowmist.medium.com","type":"other","credibility":3},{"url":"https://twitter.com/gmblcomputer","name":"twitter.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2023-08-25","event":"GMBL token launches via Liquidity Bootstrapping Pool on Camelot Exchange on Arbitrum. Presale raised approximately $100,000.","source":""},{"date":"2023-09-05","event":"GMBL.COMPUTER protocol officially launches on Arbitrum mainnet.","source":""},{"date":"2023-09-06","event":"Exploit occurs within approximately 24 hours of launch. Attacker spoof-calls GMBL's off-chain server to obtain a valid signature, withdrawing approximately 471 ETH (~$770,000) worth of GMBL tokens. A secondary referral abuse vector allows approximately 8 million GMBL to be claimed on ghost bets. GMBL token price drops approximately 75%.","source":""},{"date":"2023-09-06","event":"GMBL team suspends all contract interactions and publicly identifies the attacker. Team issues a conditional bug bounty: return 90% of funds by 9 PM EST or face legal action.","source":""},{"date":"2023-09-06","event":"Attacker returns 235 ETH (~$382,000), approximately 50% of stolen funds, to GMBL's multisig wallet. Remaining ~236 ETH is not recovered.","source":""},{"date":"2023-09-07","event":"GMBL team publishes exploit postmortem on Medium, acknowledging the vulnerability was an off-chain server signature issue and a flaw in the referral system described as a 'one-line fix.' Team commits to third-party audits before relaunch.","source":""},{"date":"2023-09-10","event":"SlowMist includes the GMBL.COMPUTER exploit in their weekly security report covering September 4-10, 2023.","source":""},{"date":"2023-11-30","event":"GMBL token reaches all-time high price of approximately $0.171.","source":""},{"date":"2025","event":"Protocol shows near-zero trading volume and approximately 19 token holders. Market cap approximately $156,000. No confirmed successful relaunch with promised security enhancements has been publicly documented.","source":"","date_original":"2025-01-01"}],"sources_used":[{"url":"https://gmblcomputer.gitbook.io/gmbl.computer","name":"gmblcomputer.gitbook.io","type":"other","archive_url":"https://web.archive.org/web/20260830001117/https://gmblcomputer.gitbook.io/gmbl.computer","credibility":3,"archive_timestamp":"2026-08-30T00:11:17+00:00"},{"url":"https://coinmarketcap.com/currencies/gmbl-computer/","name":"coinmarketcap.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://arbiscan.io/token/0xE9A5aF50874c0ef2748b5DB70104B5ccb5557f6d","name":"arbiscan.io","type":"other","archive_url":"https://web.archive.org/web/20260829123830/https://arbiscan.io/token/0xE9A5aF50874c0ef2748b5DB70104B5ccb5557f6d#transactions","credibility":3,"archive_timestamp":"2026-08-29T12:38:30+00:00"},{"url":"https://cryptorank.io/ico/gmbl-computer","name":"cryptorank.io","type":"other","archive_url":"https://web.archive.org/web/20260829235547/https://cryptorank.io/ico/gmbl-computer","credibility":3,"archive_timestamp":"2026-08-29T23:55:47+00:00"},{"url":"https://gmblcomputer.medium.com/gmbl-computer-exploit-postmortem-a09aa3297405","name":"gmblcomputer.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://beincrypto.com/defi-gmbl-computer-exploited-eth-funds-returned/","name":"beincrypto.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.web3isgoinggreat.com/single/gmblcomputer-exploit","name":"web3isgoinggreat.com","type":"other","archive_url":"http://web.archive.org/web/20260830011306/https://www.web3isgoinggreat.com/single/gmblcomputer-exploit","credibility":3,"archive_timestamp":"2026-08-30T01:13:06+00:00"},{"url":"https://coincu.com/215747-gmblcomputer-key-leaked-loss-nearly-500-eth/","name":"coincu.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://slowmist.medium.com/slowmist-weekly-security-report-september-4rd-to-10th-3310d4258f48","name":"slowmist.medium.com","type":"other","archive_url":"http://web.archive.org/web/20250909122858/https://slowmist.medium.com/slowmist-weekly-security-report-september-4rd-to-10th-3310d4258f48","credibility":3,"archive_timestamp":"2025-09-09T12:28:58+00:00"},{"url":"https://dexscreener.com/arbitrum/0x70eb6e93e1f8bfb850126e23a1964fd3db789948","name":"dexscreener.com","type":"other","archive_url":"http://web.archive.org/web/20250930162233/https://dexscreener.com/arbitrum/0x70eb6e93e1f8bfb850126e23a1964fd3db789948","credibility":3,"archive_timestamp":"2025-09-30T16:22:33+00:00"},{"url":"https://www.coingecko.com/en/coins/gmbl-computer-chip","name":"coingecko.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://coinbrain.com/coins/eth-0xa395bd32dd0ac0823bf160cd6e0db2ac08d7cdcd","name":"coinbrain.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://twitter.com/gmblcomputer","name":"twitter.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:38.251249+00:00","updated_at":"2026-08-30T05:14:09.868339+00:00"}}