Boy X Highspeed Hack
Incident Overview
BXH protocol was attacked by a private key compromise, and more than 130,000,000 $USD worth of assets stolen
BXH DeFi lending protocol was attacked by private key disclosure, by gaining control over the target smart contract, the attacker withdrew all funds at the following transaction:
https://bscscan.com/tx/0x6466cad9…74ac84
Funds recipient (attacker's contract) transferred all funds directly into the attacker's EOA:
https://bscscan.com/address/0x13b81fa9…f9d18c#tokentxns
Part of the stolen funds was bridged through Ren protocol into Bitcoin:
https://bscscan.com/tx/0xa54f7d9c…53d820
https://bscscan.com/tx/0xa317f711…cd5331
https://bscscan.com/tx/0x15ea305d…7cfb46
https://bscscan.com/tx/0xbb585cb7…d82c91
https://bscscan.com/tx/0xfa4b24b0…edcbb7
Part of the stolen funds was transferred to another EOA:
https://bscscan.com/tx/0x80636964…af6099
https://bscscan.com/tx/0xce864913…00e6ff
https://bscscan.com/tx/0x5c0b2fd4…aab411
The attacker's address:
https://bscscan.com/address/0x48c94305…c27d79
Attacker's contract, used for withdrawing assets:
https://bscscan.com/address/0x13b81fa9…f9d18c
The funds' recipient bridged tokens through AnySwap into Ethereum:
https://bscscan.com/address/0x44cc771f…9b6316#tokentxns
The address leads to the Ethereum blockchain, which has a connection with the Binance wallet:
https://etherscan.io/address/0x44cc771f…9b6316
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Boy X Highspeed, these are the critical security checks that could have prevented this incident (October 2021).
- Verify all logic paths related to Access Control are guarded by proper access controls and input validation - see the Access Control Attacks attack class for patterns
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialRelated Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Sources & References
Learn to Prevent the Next Boy X Highspeed
The Boy X Highspeed hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.