BNBpay Hack
Incident Overview
BNBpay token project experienced a rugpull, with the deployer profiting for 53,973 USD on Sep 21, 2023.
BNBpay is a BEP20 token trading on PancakeSwap. The deployer performed an exit scam by removing liquidity from the LP pool. After the exploit, the stolen funds were transferred to another EOA address and then deposited into TornadoCash, making it difficult to trace the funds.
Deployer Address:
https://bscscan.com/address/0xcE389248…578D9d
Scammer Address:
https://bscscan.com/address/0x9D323c34…7cCf15
Liquidity Removal Transaction:
https://bscscan.com/tx/0x8e99cb2f…2a5b1f
Tornado Cash Deposit Transaction: 0x5ffa17d2…fb245e
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to BNBpay, these are the critical security checks that could have prevented this incident (September 2023).
- Verify all logic paths related to Rugpull are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
-
01
Source 1 https://hacked.slowmist.io/?c=BSC
Learn to Prevent the Next BNBpay
The BNBpay hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.