BSC Token Hub Hack
What happened
BSC Token Hub, the native bridge between BNB Beacon Chain and BNB Smart Chain, was exploited on October 6, 2022. An IAVL Merkle-proof validation flaw let a forged proof validate an arbitrary transfer payload. Two forged packages caused TokenHub to release 2 million BNB, valued at roughly $586 million at the time.
BNB Chain halted BSC and later patched the issue through a hard fork.
The bridge's IAVL Merkle-proof validation did not correctly bind a proven tree structure to the transfer payload being executed. An authorized relayer could submit an adversarial proof that validated an arbitrary package. Cross-chain proof verification must be tested at the actual node or precompile boundary with malformed proof trees and adversarial payload binding, not only with valid-message paths.
Case & protocol details
Attack Timeline
The attacker registered as a relayer and submitted a forged cross-chain transfer package. A flaw in the IAVL proof-validation precompile accepted an attacker-supplied proof for an arbitrary payload. CrossChain processed the accepted package and instructed TokenHub to release 1 million BNB.
A second forged package repeated the process for another 1 million BNB. The attacker then moved some value through lending and cross-chain routes before BSC was halted.
Funds Recovery
Recovered
$465.5M
Net Loss
$120,716,000
Evidence & learning
Sources and on-chain records
- report Report bnbchain.org
- report Post-mortem rekt.news
- report Report twitter.com
- transaction Transaction bscscan.com
- transaction Transaction bscscan.com
- analysis Coinbase BSC Token Hub investigation coinbase.com
- analysis Verichains Binance Bridge analysis blog.verichains.io
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.