Brinc Finance Hack
What happened
The address marked as "hacker" on Etherscan:
https://etherscan.io/address/0x6B0b6132…8f67Bb
1. The contract deployer of the staking contract invoked transferOwnership() at:
https://etherscan.io/tx/0x09ae252d…a00df4
2. The newOwner was set to "hacker's" address:
https://etherscan.io/address/0x6B0b6132…8f67Bb
3. The contract deployer of the staking contract upgraded implementation of the contract at:
https://etherscan.io/tx/0xdc7b9865…efcfa7
4. The new implementation is:
https://etherscan.io/address/0x1eC83036…bd8f3D#code
5. The new implementation includes rescueTokens() function which allows the owner to withdraw all tokens balance from the contract:
https://etherscan.io/address/0x1eC83036…bd8f3D#code#F1#L817
6. The "hacker" invokes rescueTokens() at:
https://etherscan.io/tx/0x729c2888…26da27
https://etherscan.io/tx/0x03bae1ef…c510db
7. The "hacker" burns BRC and receives DAI in exchange:
https://etherscan.io/tx/0x160471a4…da15bc
8. The "hacker" swaps gBRC for DAI on SushiSwap at:
https://etherscan.io/tx/0xfc559fad…e551f7
9. Stolen DAI were exchanged on ETH at:
https://etherscan.io/tx/0xc16be592…5fc9c9
10. Received ETH were deposited into Tornado Cash mixer at multiple transactions:
https://bloxy.info/txs/calls_from/0x6b0b6132…8f67bb?signature_id=994162&smart_contract_address_bin=0x722122df…5b6967
The hacker was funded by the contract deployer before the incident:
https://etherscan.io/tx/0xc95e14ea…0c4944
Protocol details
Security review history
- CertiK View report
Evidence
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.