BNB42 Hack

TOTAL LOST $2.6M
Medium Rugpull

What happened

The address involved in the scam:

https://bscscan.com/address/0x9b74fde5…d6eb8f

The address involved in the scam deployed the unverified contract which contained withdraw() function that allows only the owner to withdraw the entire total BNB (eth.balance(this.address) wei) to the owner’s address.

The contract deployer invoked withdraw() to transfer 6,445.42 BNB onto own address at:

https://bscscan.com/tx/0x749215eb…cf9414

Stolen funds were distributed to a bunch of external addresses and deposited into the Tornado Cash mixer.

Case & protocol details

Classification Yield Aggregator
Protocol Type Exit Scam/Rugpull
Official Website bnb42.com/
Protocol Twitter/X @bnb42i

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.