AK1111 Hack
What happened
On November 24, 2024, the Akashalife token AK1111 on BNB Chain was drained of about $31,500. Its contract exposed a function named nonblockingLzReceive1() that anyone could call, and the function minted AK1111 to an address chosen by the caller. The attacker minted a large amount of free AK1111 and sold it into the token's PancakeSwap pool for BSC-USD. TenArmor noted the function was probably never meant to be public.
Exploit transaction: 0xc29c98da0c14f4ca436d38f8238f8da1c84c4b1ee6480c4b4facc4b81a013438. Attacker: 0xCe21C6e4fa557A9041FA98DFf59A4401Ef0a18aC. Attack contract: 0xbFD7280B11466bc717EB0053A78675aed2C2E388.
How it happened
- The attacker's contract called
nonblockingLzReceive1()on the AK1111 token directly, with its own address as the recipient. The function has no caller check, so it minted new AK1111 to the attacker. - The DeFiHackLabs reproduction mints an amount equal to the pool's whole AK1111 balance.
- The attacker sold the minted AK1111 for BSC-USD through the PancakeSwap router, draining about $31,500 of the pool's stablecoin side.
Protocol details
Evidence
- report TenArmor Security Alert: AK1111 on BSC, ~$31.5K loss x.com
- transaction BscScan transaction 0xc29c98da...3438 (Wayback copy, 2024-12-14) web.archive.org
- analysis DeFiLlama defillama.com
- analysis DeFiHackLabs Ak1111_exp.sol raw.githubusercontent.com
- analysis SlowMist Hacked, page 27 (Akashalife (AK1111), 2024-11-24) hacked.slowmist.io
- analysis Nov 2024 - AkashaLife/AK1111 Free Public Minting Vulnerability - $32k (Quadriga Initiative) quadrigainitiative.com
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.