BRA Token Hack
Incident Overview
On January 10, 2023, BRA token was attacked, and the hacker was able to steal funds worth $225,000 USD.
On January 10, 2023, a hack occurred that targeted the BRA token resulting in the theft of funds worth 819 WBNB, which is equivalent to approximately $225,000. The hack was made possible by a logical vulnerability that allowed the attacker to exploit the transfer function, which gave them twice the rewards if the sender and recipient were a pair.
The attacker exploited the vulnerability by obtaining a 1,400 WBNB flash loan before exchanging 1,000 WBNB for 10.5K BRA tokens. They then transferred all the acquired BRA tokens to the Pancakeswap pair. Next, they used the "skim()" function and invoked the BRA contract's transfer function to receive rewards. The "skim()" function acts as a recovery mechanism if the number of tokens supplied to a pair exceeds the two uint112 storage spaces for reserves.
In this case, the attacker provided the pair as the recipient address, and BRA reverted to the pair, resulting in the doubling of the BRA amount after a single skim. The attacker repeated this method 100 times, which led to a significant increase in the contract pair's BRA balance.
The attacker then returned 1.675K WBNB tokens and repaid the 1.4K WBNB token flash loan, which generated a profit of 675 WBNB that was sent to their address. The attacker carried out the same attack again and took 144 WBNB in profit from the BRA contract.
Exploit TX:
https://bscscan.com/tx/0x6759db55β¦5d4047
Wallet with funds:
https://debank.com/profile/0x67a909f2β¦2d0795
Incident Report
Protocol Information
Market Context at Time of Hack
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to BRA Token, these are the critical security checks that could have prevented this incident (January 2023).
- Verify all logic paths related to Flash Loan Attack are guarded by proper access controls and input validation - see the Flash Loans Attacks attack class for patterns
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialRelated Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Sources & References
Learn to Prevent the Next BRA Token
The BRA Token hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.