Bitcoin Savings and Trust Hack

TOTAL LOST $4.6M
Medium Rugpull

Summarize with AI

Affected Chain 2012 Incident surface
Recovered - No recovery reported
All-Time Rank #452 By amount stolen
Protocol Type Exit Scam/Rugpull Target category

Incident Overview

Bitcoin Savings & Trust (abbreviated as BST) was a Ponzi scheme operated by Trendon Shavers (then known as Pirate). It was launched in November 2011 as First Pirate Savings & Trust. Pirate claimed to have been selling bitcoins to some local tight-lipped buyers, and that he started BST to provide more volume to these buyers. By selling invested bitcoins at a high rate and rebuying them at the market price, Pirate was supposedly able to offer a very high-yield interest rate of 7% per week. This rate attracted many investors, and Pirate claimed that over 500,000 bitcoins had been deposited.

After accumulating an ever-larger amount of bitcoin, transactions were becoming difficult and expensive. Pirate attempted to reduce the strain by lowering the interest rate, but this sparked unrest and mass withdrawals. After a discussion with his clients, Pirate decided to close BST and announced his intentions to return all owned bitcoins. After repaying at least 11 small beneficiaries, BST suddenly announced a default on August 28, 2012. It was later revealed that the missing money went towards "rent, car-related expenses, utilities, retail purchases, casinos, and meals."

Incident Report

Protocol / Project Bitcoin Savings and Trust
Date of Incident
Attack Technique Rugpull
Classification CeFi
Primary Source View Post-Mortem

Protocol Information

Protocol Type Exit Scam/Rugpull
Team Anonymous
Source Code Unverified

What the Attacker Needed to Succeed

Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.

Technical Knowledge Deep understanding of rugpull and Solidity and EVM internals
Capital Required Seed capital to cover gas and initial position setup
On-Chain Access Ability to interact with smart contracts and deploy a custom exploit contract
Protocol Analysis Identification of the exploitable vulnerability in Bitcoin Savings and Trust's contract logic - root cause: cefi
Execution Speed Precise transaction ordering and timing to exploit the vulnerability within a single atomic block
Obfuscation Plan A strategy to launder and move stolen funds - typically through mixers, cross-chain bridges, or decentralized DEX swaps to resist tracing

What Auditors Should Check

Could this have been caught in audit? Hard to catch — private key / OpSec failures are outside smart contract audit scope

If you're auditing a protocol with similar architecture to Bitcoin Savings and Trust, these are the critical security checks that could have prevented this incident (July 2012).

  • Verify all logic paths related to Rugpull are guarded by proper access controls and input validation
  • Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs

Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.

Free Trial

Sources & References

Learn to Prevent the Next Bitcoin Savings and Trust

The Bitcoin Savings and Trust hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.

Recreate exploit patterns safely Free Trial