Brinc Finance Hack

Reported loss $1.1M
Other

What happened

The address marked as "hacker" on Etherscan:

https://etherscan.io/address/0x6B0b6132…8f67Bb

1. The contract deployer of the staking contract invoked transferOwnership() at:

https://etherscan.io/tx/0x09ae252d…a00df4

2. The newOwner was set to "hacker's" address:

https://etherscan.io/address/0x6B0b6132…8f67Bb

3. The contract deployer of the staking contract upgraded implementation of the contract at:

https://etherscan.io/tx/0xdc7b9865…efcfa7

4. The new implementation is:

https://etherscan.io/address/0x1eC83036…bd8f3D#code

5. The new implementation includes rescueTokens() function which allows the owner to withdraw all tokens balance from the contract:

https://etherscan.io/address/0x1eC83036…bd8f3D#code#F1#L817

6. The "hacker" invokes rescueTokens() at:

https://etherscan.io/tx/0x729c2888…26da27

https://etherscan.io/tx/0x03bae1ef…c510db

7. The "hacker" burns BRC and receives DAI in exchange:

https://etherscan.io/tx/0x160471a4…da15bc

8. The "hacker" swaps gBRC for DAI on SushiSwap at:

https://etherscan.io/tx/0xfc559fad…e551f7

9. Stolen DAI were exchanged on ETH at:

https://etherscan.io/tx/0xc16be592…5fc9c9

10. Received ETH were deposited into Tornado Cash mixer at multiple transactions:

https://bloxy.info/txs/calls_from/0x6b0b6132…8f67bb?signature_id=994162&smart_contract_address_bin=0x722122df…5b6967

The hacker was funded by the contract deployer before the incident:

https://etherscan.io/tx/0xc95e14ea…0c4944

Protocol details

Classification Yield Aggregator
Protocol Type Yield
Affected asset / contract BRC, gBRC, sgBRC
Protocol links Website @BrincFi

Security review history

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.