Bancor Hack
What happened
In June 2020, a Bancor v0.6 vulnerability exposed users who had granted the protocol infinite ERC-20 approvals. A mistakenly public safeTransferFrom path let callers transfer approved funds. Bancor began an emergency white-hat sweep, but two front-runners captured part of the vulnerable balance before it could be moved to safety.
A public safeTransferFrom function could consume users' infinite ERC-20 approvals. Approval-bearing contracts must strictly restrict transfer authority, minimize approval scope, and ensure emergency recovery paths cannot be front-run into a loss.
Case & protocol details
Attack Timeline
The v0.6 contracts deployed on 16 June exposed a safeTransferFrom function that should not have been publicly callable. Because direct-swap users had left infinite approvals, any caller could use that path to pull their approved tokens. Bancor's emergency response started a white-hat sweep to migrate vulnerable balances to a safe wallet.
1inch's incident analysis identifies 62 Bancor rescue transactions that moved about $409,656, while front-runners captured about $135,229. The larger $545K figure is total wallet outflow during the rescue, not an amount that should be presented as attacker loss. The incident is separate from Bancor's 2018 breach.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report blog.1inch.io
- report The Block Bancor vulnerability report theblock.co
- transaction Transaction etherscan.io
- analysis 1inch Bancor v0.6 incident analysis blog.1inch.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.