ArenaPlayAPC Hack
Incident Overview
A soft rugpull was noticed in the $APC token. The team took away approximately 1200 $BNB in profit.
The creator of the token deployed the contract to the BSC network, where 100M tokens were minted on the address (B):
https://bscscan.com/tx/0x0fb8c25a…84f2b8
Address (B) sent 150k $APC to the address (C) in this transaction:
https://bscscan.com/tx/0x96510bd2…397322
Then address (C) interacted with address (D) that later transferred 1200 $BNB through Tornado.cash:
Interactions transaction: https://bscscan.com/tx/0x10978099…503762
Address (E) received 1M $USDT from Binance Hot Wallet and 14 $BNB from Tornado.cash which then distributed funds to the bot addresses:
https://bscscan.com/tx/0x94609a43…11723a
Bots started creating fake trade volume in order to attract investor's attention in this project. When investors deposited funds into the token, part of the money ~1.2M $USDT was sent to address (D) in multiple transactions.
Example transactions:
1) https://bscscan.com/tx/0x542f6f8c…d2edf3
2) https://bscscan.com/tx/0x0246a322…48f018
3) https://bscscan.com/tx/0xb7a52cc6…0557e0
Then 1200 $BNB was withdrawn via Tornado.cash.
As the time writing information on this case is scarce. More sources will be added if the case should develop.
Involved addresses:
Token creator (A): https://bscscan.com/address/0x4e6b2534…dcf81f
Address (B): https://bscscan.com/address/0x34242a39…6b3e32
Address (C): https://bscscan.com/address/0xd73fc94a…f8d9de
Address (D): https://bscscan.com/address/0x0fc7ce89…e5dcbe
Address (E): https://bscscan.com/address/0x17034afd…1E08AC
Example bot addresses:
Address (F): https://bscscan.com/address/0xea2d5cac…495777
Address (G): https://bscscan.com/address/0x03a018ef…bd8a0f
Address (H): https://bscscan.com/address/0xcdb2a8d0…ccd73f
Token creation: https://bscscan.com/tx/0x0fb8c25a…84f2b8
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to ArenaPlayAPC, these are the critical security checks that could have prevented this incident (July 2022).
- Verify all logic paths related to Rugpull are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
Learn to Prevent the Next ArenaPlayAPC
The ArenaPlayAPC hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.