AIRWA Hack

TOTAL LOST $34K
Low Access Control Attacks bsc

What happened

On April 4, 2025, AIRWA token on BNB Smart Chain (BSC) was exploited for approximately $34,000 due to a misconfigured public setBurnRate() function.

The vulnerability stemmed from the setBurnRate() function in the AIRWA token contract being publicly accessible. The attacker called setBurnRate(980)—an extremely high burn percentage—and then executed a transfer(pair, 0). This combination caused the pair’s tokens to be burned, manipulating the liquidity pool and allowing the attacker to extract value.

Case & protocol details

Classification Token / Access Control
Protocol Type Exploit/Other
Smart Contract Language Solidity

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.