AK1111 Hack

Reported loss $32K
BNB Chain
Improper Access Control

What happened

On November 24, 2024, the Akashalife token AK1111 on BNB Chain was drained of about $31,500. Its contract exposed a function named nonblockingLzReceive1() that anyone could call, and the function minted AK1111 to an address chosen by the caller. The attacker minted a large amount of free AK1111 and sold it into the token's PancakeSwap pool for BSC-USD. TenArmor noted the function was probably never meant to be public.

Exploit transaction: 0xc29c98da0c14f4ca436d38f8238f8da1c84c4b1ee6480c4b4facc4b81a013438. Attacker: 0xCe21C6e4fa557A9041FA98DFf59A4401Ef0a18aC. Attack contract: 0xbFD7280B11466bc717EB0053A78675aed2C2E388.

How it happened

  1. The attacker's contract called nonblockingLzReceive1() on the AK1111 token directly, with its own address as the recipient. The function has no caller check, so it minted new AK1111 to the attacker.
  2. The DeFiHackLabs reproduction mints an amount equal to the pool's whole AK1111 balance.
  3. The attacker sold the minted AK1111 for BSC-USD through the PancakeSwap router, draining about $31,500 of the pool's stablecoin side.

Protocol details

Classification Access Control
Protocol Type DeFi Protocol
Implementation language Solidity

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.