BSC Token Hub Hack
Incident Overview
BNB Smart Chain's native cross-chain bridge between BNB Beacon Chain and BNB Smart Chain was exploited, which resulted in minting 2,000,000 $BNB to the hacker's address.
The native cross-chain bridge between BNB Beacon Chain (BEP2) and BNB Smart Chain (BEP20), also known as BNB Token Hub was exploited. The hacker used a low-level proof vulnerability and minted 2,000,000 $BNB to their address. Consequently, the hacker began bridging the funds to Fantom and Ethereum chains.
The security experts in collaboration with validators were able to save the majority of the funds. The hacker managed to bridge 127,000,000 $USD using AnySwap and Stargate bridges, with 53% of the stolen funds going to Ethereum, 33% to Fantom, and the rest to other chains. Tether blacklisted the attacker's address.
The remaining 459,000,000 $USD worth of assets were left frozen in the attacker's address.
Attacker address:
https://bscscan.com/address/0x489a8756…f79bec
Malicious transactions:
https://bscscan.com/tx/0x05356fd0…e5c57a
https://bscscan.com/tx/0xebf83628…fe3b8b
Affected contracts:
https://bscscan.com/address/0x00000000…002000
https://bscscan.com/address/0x00000000…001004
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to BSC Token Hub, these are the critical security checks that could have prevented this incident (October 2022).
- Verify all logic paths related to Other are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialFunds Recovery
Recovered
$465.5M
Net Loss
120715999
Sources & References
- 01
-
02
Source 2 https://rekt.news/bnb-bridge-rekt/
- 03
Learn to Prevent the Next BSC Token Hub
The BSC Token Hub hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.