293 hack event(s)
Description of the event: GPU on BNBChain was attacked, with a loss of about $32,000. There is a logic vulnerability in the _transfer function of the contract. When transferring money to yourself, the balance will increase by the amount of the transfer.
Amount of loss: $ 32,000 Attack method: Contract Vulnerability
Description of the event: OSN on BNBChain is suspected to have been attacked. The attacker initiated multiple attack transactions, resulting in a loss of ~$110K. The attacker took advantage of the OSNLpDividendTracker contract which sells its own tokens as a reward for users adding liquidity.
Amount of loss: $ 110,000 Attack method: Contract Vulnerability
Description of the event: Saturn, the new token issuance protocol, was exploited on the BNB chain, which resulted in a loss of 14.16 BNB, worth approximately $8,343. The protocol would reportedly burn and sync the asset amount before any prior token transfers, which led to a price manipulation attack that caused their SATURN/WBNB pool to be entirely empty.
Amount of loss: $ 8,343 Attack method: Price Manipulation
Description of the event: According to intelligence from the SlowMist Security Team, the YIEDL project on the BSC chain was attacked, with the attacker stealing approximately $300,000. In this incident, the reason lies in the contract’s failure to adequately validate the external parameter(dataList) provided by the user during the processing of the redeem function call. This parameter is critical data for controlling asset exchanges, typically containing specific transaction instructions or routing information. The attacker maliciously constructed this external parameter, enabling unauthorized asset transfers.
Amount of loss: $ 300,000 Attack method: Contract Vulnerability
Description of the event: Shortly after the deployment of the FENGSHOU (NGFS) token, it was attacked, resulting in a loss of approximately $191,000. The vulnerability lies in a public `delegateCallReserves` function which allows the attacker to set an arbitrary address to a UniSwapV2 proxy.
Amount of loss: $ 191,000 Attack method: Contract Vulnerability
Description of the event: Users reported abnormal activity on the trading platform of the DeFi asset management protocol Velvet Capital on April 23rd. When attempting to connect to the frontend, users were prompted to approve their wallet's access permissions for the protocol.
Amount of loss: - Attack method: Frontend Attack
Description of the event: The Fake Safe Token (SAFE) on BNBChain is suspected of a rug pull, and the current token price has dropped by 100%.
Amount of loss: $ 752,683 Attack method: Rug Pull
Description of the event: Z123 on BSC was attacked by a hacker due to a contract vulnerability, resulting in a loss of approximately $136k. The .update() function of Z123 was repeatedly called which burned extra tokens and inflated the price.
Amount of loss: $ 136,000 Attack method: Contract Vulnerability
Description of the event: The Fake Cruiz (CRUIZ) on BNBChain is suspected of a rug pull, and the current token price has dropped by 100%.
Amount of loss: $ 38,556 Attack method: Rug Pull
Description of the event: Fake PRCL on the BNB Chain appears to have exit scammed, resulting in a 100% price drop and causing losses exceeding $100,000.
Amount of loss: $ 100,000 Attack method: Rug Pull
Description of the event: Token issuance protocol Mars was attacked and lost about 1M MARS 和 137 个 WBNB.
Amount of loss: $ 98,000 Attack method: Unknown
Description of the event: Fake JILLBODEN on BNBChain is suspected of a rug pull, and the current token price has dropped by 100%.
Amount of loss: $ 335,339 Attack method: Rug Pull
Description of the event: Fake VDZ on BNBChain is suspected of a rug pull, and the current token price has dropped by 100%.
Amount of loss: $ 323,088 Attack method: Rug Pull
Description of the event: The GFA token was exploited on the BNB chain, which resulted in a loss of assets worth approximately $15,000. The root cause of the exploit is a lack of access control. The vulnerable contracts had functions for calculating rewards, for which anyone could invoke a call to them. The hacker was able to manually calculate and generate the rewards and drain the tokens. The exploiter has already laundered the stolen assets into Tornado Cash.
Amount of loss: $ 15,000 Attack method: Contract Vulnerability
Description of the event: Squid Game (SQUID) is a meme token on the BNB chain. On April 8, 2024, the SQUID Game was exploited on the BNB chain due to a smart contract vulnerability, which resulted in a loss of assets worth approximately $87,000. The root cause of the exploit is a faulty logic design within their swap contract.
Amount of loss: $ 87,000 Attack method: Contract Vulnerability
Description of the event: UPS on BNBChain was attacked and lost ~$30K.
Amount of loss: $ 30,000 Attack method: Unknown
Description of the event: Wall Street Memes (WSM)’s pre-sale contract was attacked, resulting in a loss of ~2.5M WSM, worth of ~$18,000.
Amount of loss: $ 18,000 Attack method: Flash Loan Attack
Description of the event: The DeFi protocol OpenLeverage has been attacked, resulting in a loss of approximately $260,000. In light of this, OpenLeverage has decided to discontinue the OpenLeverage trading and lending protocol. OpenLeverage is initiating processes for users to close trades/borrowings and withdraw funds safely. All protocol actions will remain paused until withdrawal processes begin early next week.
Amount of loss: $ 260,000 Attack method: Contract Vulnerability
Description of the event: The project ZongZiFa on BSC was exploited through a flash loan, resulting in a loss of approximately $229,000. The attacker manipulated the price of ZongZi to gain invitation rewards.
Amount of loss: $ 229,000 Attack method: Flash Loan Attack
Description of the event: The astrology-based project Lucky Star Currency rug-pulled in October 2023, resulting in a loss of $1.1 million. On March 22, 2024, ownership of the project was transferred to a malicious smart contract, which then drained tokens valued at almost $300,000 from those who still held them.
Amount of loss: $ 300,000 Attack method: Rug Pull