Bitmor Hack

Reported loss $6K
Base
Token Approval Abuse

What happened

On May 25, 2026, approximately $6,000 was stolen from users of Bitmor, a Bitcoin-focused DeFi platform on Base.

Technical root cause

The DCA contract could use active user token allowances without adequately limiting its transfer authority, allowing an attacker to abuse existing approvals.

How it happened

A flaw in Bitmor's DCA contract allowed an attacker to use active user token approvals to withdraw funds.

Protocol details

Classification Access Control
Protocol Type DeFi Protocol
Implementation language Solidity

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.