BBT Hack

Reported loss Not disclosed
Ethereum
Unknown

What happened

On March 12, 2024, an attacker minted a huge supply of the BBT token on Ethereum and sold it for about 5.06 ETH. BBToken.mint() accepted a caller only if an external registry contract returned that caller's address for one of the protocol's modules (Savings, Referral, Insurance, Income or LockedSavings). However, setRegistry() had no access control, so anyone could point the token at a registry of their own.

The attacker installed a fake registry that listed its own contract as an authorized module, minted tokens, and dumped them into the token's Uniswap V2 liquidity. DeFiHackLabs files the incident as a business logic flaw, but the underlying failure is a missing access check on a privileged setter.

How it happened

  1. The attacker EOA 0xc9a5643ed8e4cd68d16fe779d378c0e8e7225a54 deployed an attack contract, which used CREATE2 to deploy a fake registry whose getContractAddress() returned the attack contract for any name.
  2. The attack contract called BBT.setRegistry(fakeRegistry). The function had no owner or role check.
  3. It called BBT.mint() for an enormous amount. _isAuthorizedAddress() asked the fake registry for the Savings module address, got back the attack contract, and allowed the mint.
  4. It sold the minted BBT through Uniswap V2, directly to WETH and also along a BBT to BLM to USDC to WETH path. This drained about 5.06 ETH of liquidity in tx 0x4019890fe5a5bd527cd3b9f7ee6d94e55b331709b703317860d028745e33a8ca.

Protocol details

Classification Protocol Logic
Protocol Type DeFi Protocol
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.