BetterBank Hack
Incident Overview
Better Bank, a DeFi platform on PulseChain, was exploited for approximately $5 million in assets including 890.8 million pDai, 9.05 billion PulseX, and 7.41 billion Pulse tokens. The attacker exploited a vulnerability in the bonus Esteem minting contract, converting stolen funds to 215 ETH (~$983,000) and transferring them to Ethereum via Tornado Cash-funded addresses.
The attack exploited a vulnerability in an audited contract responsible for minting bonus Esteem tokens on Favor purchases. The exploiter discovered they could mint excessive bonus Esteem by purchasing Favor using a trading pair that wasn't part of Better Bank's intended pairs - specifically a pair containing a worthless token they could mint infinitely. The attacker created a near-infinite loop by minting bonus Esteem through purchases with the manipulated pair, converting that Esteem into Favor via the Smelter contract, then selling the Favor pool to zero regardless of tax implications.
This sophisticated attack drained 890,874,504.36 pDai, 9,051,537,270.60 PulseX, and 7,409,330,692.99 Pulse tokens worth approximately $5 million. Better Bank emergency paused the protocol within 10 minutes of detecting the attack. The team is offering a 20% bounty for identifying the attacker and has requested return of 700M pDai tokens, while planning to rebuild contracts, airdrop new tokens to legitimate holders, and use treasury assets to cover the substantial bad debt created by the exploit.
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to BetterBank, these are the critical security checks that could have prevented this incident (August 2025).
- Verify all logic paths related to Infinite Mint and Dump / Other are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSecurity Audit History
- Audit Report 1 Report
Sources & References
Learn to Prevent the Next BetterBank
The BetterBank hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.