BGE Hack
Incident Overview
The token deployer sold off BGE that had been preminted to their address on PancakeSwap.
Details of the Exit scam
13M of the BGE were preminted to the token’s deployer address in the contract’s creation transaction.
The deployer dumped 705,000 BGE on PancakeSwap in 23 transactions having gained $426,892.
The deployer address:
https://bscscan.com/address/0xcdf77769…e1c2d8
Example sell transactions:
https://bscscan.com/tx/0xb54485b0…8b82d7
https://bscscan.com/tx/0x3ac49ba7…d42a9f
https://bscscan.com/tx/0xabcd55d3…c15d3b
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to BGE, these are the critical security checks that could have prevented this incident (December 2022).
- Verify all logic paths related to Rugpull are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
- 01
-
02
Web Archive https://archive.ph/wUGdh
Learn to Prevent the Next BGE
The BGE hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.