Arcade Hack

Reported loss $5K
Access Control

What happened

On March 17 2025 the Arcade Token on BSC was exploited due to a vulnerability in its public signer mechanism with a loss of about 5k USD.

The contract had an insecure public signer verification system, making it susceptible to signature replay attacks. The attacker exploited this by crafting valid signatures that the contract mistakenly recognized as legitimate, allowing them to mint and transfer tokens without proper authorization. As a result, a significant amount of funds were drained.

Protocol details

Classification Token
Protocol Type Exploit/Access control
Affected asset / contract ARC
Protocol links Website @_ArcadeToken

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.