BBT Hack
What happened
On March 12, 2024, an attacker minted a huge supply of the BBT token on Ethereum and sold it for about 5.06 ETH. BBToken.mint() accepted a caller only if an external registry contract returned that caller's address for one of the protocol's modules (Savings, Referral, Insurance, Income or LockedSavings). However, setRegistry() had no access control, so anyone could point the token at a registry of their own.
The attacker installed a fake registry that listed its own contract as an authorized module, minted tokens, and dumped them into the token's Uniswap V2 liquidity. DeFiHackLabs files the incident as a business logic flaw, but the underlying failure is a missing access check on a privileged setter.
How it happened
- The attacker EOA
0xc9a5643ed8e4cd68d16fe779d378c0e8e7225a54deployed an attack contract, which usedCREATE2to deploy a fake registry whosegetContractAddress()returned the attack contract for any name. - The attack contract called
BBT.setRegistry(fakeRegistry). The function had no owner or role check. - It called
BBT.mint()for an enormous amount._isAuthorizedAddress()asked the fake registry for the Savings module address, got back the attack contract, and allowed the mint. - It sold the minted BBT through Uniswap V2, directly to WETH and also along a BBT to BLM to USDC to WETH path. This drained about 5.06 ETH of liquidity in tx
0x4019890fe5a5bd527cd3b9f7ee6d94e55b331709b703317860d028745e33a8ca.
Protocol details
Evidence
- address Etherscan verified source: BBToken 0x3541499cda8CA51B24724Bb8e7Ce569727406E04 etherscan.io
- analysis DeFiLlama defillama.com
- analysis DeFiHackLabs BBT_exp.sol raw.githubusercontent.com
- analysis 8olidity alert on BBT (X, via fxtwitter mirror) api.fxtwitter.com
- analysis DeFiHackLabs README 2024 entry '20240312 BBT - business logic flaw' raw.githubusercontent.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.