CF Token Hack
What happened
On April 11, 2022, the CF token of the Creat Future project on BNB Smart Chain was drained of about $1.9 million, including liquidity from the PancakeSwap CF-USDT pair. PeckShield reported that the token contract let anyone drain other holders' CF balances: its internal _transfer helper had been declared public. CF's price fell about 90% shortly afterwards.
U.Today reported that the project's social media accounts had been deleted by the time the exploit was found, and some community members suspected an inside job; that has not been confirmed.
How it happened
- In the CF token contract
0x8B7218CF6Ac641382D7C723dE8aA173e98a80196,_transfer(address from, address to, uint256 amount)was markedpublicinstead ofinternal. It checked only thatfromwas not the zero address and thatamountwas positive, plus a whitelist check that applied only when theuseWhiteListSwithflag was on. - Anyone could therefore call
_transferwith another account asfromand their own address asto, with no allowance or signature. - The attacker used this to pull CF directly out of the PancakeSwap CF-USDT pair
0x7FdC0D8857c6D90FD79E22511baf059c0c71BF8band other holders; DeFiHackLabs' reproduction does this with a single_transfercall from the pair to the attacker. - Draining the pair and dumping CF took about $1.9 million in value and crashed the token price by roughly 90%.
Protocol details
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.