Atlantis Loans Hack

Reported loss $2.5M
BNB Chain
Governance takeover and approval drain

What happened

In June 2023, a malicious governance proposal gave an attacker control of Atlantis Loans contracts on BNB Chain. The attacker installed code that drained wallets with outstanding token approvals. Revoke.cash reports over $2.5 million stolen.

Technical root cause

A governance takeover enabled malicious contract updates that abused existing token allowances. Affected assets came from approved user wallets.

How it happened

  1. The abandoned protocol's contracts and users' token approvals remained active.
  2. The attacker passed a governance proposal and updated contracts with malicious code.
  3. The updated contracts transferred assets from wallets that had authorized Atlantis Loans to spend their tokens.

Protocol details

Classification Protocol Logic / Governance Takeover
Protocol Type Lending
Affected asset / contract ATL
Implementation language Solidity
Protocol links Website @atlantis_loans

Security review history

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.