Casper DeFi Hack
What happened
In the official post mortem, the project team says that their Solidity developer left the minting possibility in the contract constructor.
Their Solidity developer is the contract deployer as well:
https://ftmscan.com/address/0xe6a02584…19782b
The contract deployer invoked the mint() function in the following transactions:
https://ftmscan.com/tx/0xf296baf2…05f29d
https://ftmscan.com/tx/0x4d02eac3…8d4a36
https://ftmscan.com/tx/0x86360b2e…7ea35d
The minted tokens were sold by the contract deployer multiple times:
https://ftmscan.com/txs?a=0xe6a02584…19782b&p=1
Received WFTM tokens were exchanged on BNB tokens and bridged to the BSC:
https://ftmscan.com/tx/0xf1d92544…5586f8
https://ftmscan.com/tx/0xb099c04d…b6fd80
The token recipient on the Binance Smart Chain:
https://www.bscscan.com/address/0xe6a02584…19782b
The stolen 516.91 BNB tokens were exchanged on BTCB at:
https://www.bscscan.com/tx/0xf4bc083c…41c41b
BTCB tokens were bridged through Ren:
https://www.bscscan.com/tx/0x2c22bd5f…6111c2
According to the announcement below, stolen funds were returned:
https://casperdefi.medium.com/casper-defi-post-mortem-after-casper-token-hack-part-2-1bae9a65ae5c
Case & protocol details
Funds Recovery
Recovered
$190K
Net Loss
$0
Evidence & learning
Sources and on-chain records
- report Report casperdefi.medium.com
- report Report casperdefi.medium.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.