CF Token Hack

Reported loss $1.9M
BNB Chain
Improper Access Control

What happened

On April 11, 2022, the CF token of the Creat Future project on BNB Smart Chain was drained of about $1.9 million, including liquidity from the PancakeSwap CF-USDT pair. PeckShield reported that the token contract let anyone drain other holders' CF balances: its internal _transfer helper had been declared public. CF's price fell about 90% shortly afterwards.

U.Today reported that the project's social media accounts had been deleted by the time the exploit was found, and some community members suspected an inside job; that has not been confirmed.

How it happened

  1. In the CF token contract 0x8B7218CF6Ac641382D7C723dE8aA173e98a80196, _transfer(address from, address to, uint256 amount) was marked public instead of internal. It checked only that from was not the zero address and that amount was positive, plus a whitelist check that applied only when the useWhiteListSwith flag was on.
  2. Anyone could therefore call _transfer with another account as from and their own address as to, with no allowance or signature.
  3. The attacker used this to pull CF directly out of the PancakeSwap CF-USDT pair 0x7FdC0D8857c6D90FD79E22511baf059c0c71BF8b and other holders; DeFiHackLabs' reproduction does this with a single _transfer call from the pair to the attacker.
  4. Draining the pair and dumping CF took about $1.9 million in value and crashed the token price by roughly 90%.

Protocol details

Classification Access Control
Protocol Type Token
Implementation language Solidity

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.