Aspiring Cooperation Community Hack
Incident Overview
ACC token rugpulled by the scammer, removing liquidity worth 173,462 USDT from PancakeSwap pool on Aug 23, 2023.
Aspiring Cooperation Community (ACC) is a BEP20 token trading on PancakeSwap. The scammer received tokens from the initial token holder and then removed liquidity from the LP pool on Aug 23, 2023. Previously, the scammer had added liquidity for 50,816 USDT on March 30.
After the rugpull, the stolen funds were transferred to another EOA and then distributed between multiple addresses.
Deployer Address:
https://bscscan.com/address/0xBcA8ec8D…E04Cc5
Initial Token Holder Address:
https://bscscan.com/address/0x297717c1…91f1da
Scammer Address:
https://bscscan.com/address/0x3557EF18…205bE0
Liquidity Adding Transaction:
https://bscscan.com/tx/0x129d77c9…b6a2d7
Liquidity Removal Transaction:
https://bscscan.com/tx/0x23686c0f…7e4499
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Aspiring Cooperation Community, these are the critical security checks that could have prevented this incident (August 2023).
- Verify all logic paths related to Rugpull are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
Learn to Prevent the Next Aspiring Cooperation Community
The Aspiring Cooperation Community hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.