Crosswise Hack

TOTAL LOST $879K
Low Access Control Attacks bsc

What happened

The transaction behind the attack:

https://bscscan.com/tx/0xd02e444d…5f479b

The attacker's address:

https://bscscan.com/address/0x74834611…fc5089

The attack was made possible by the public disclosure of a privileged function, which is subsequently used to set the trustedForwarder and further hijack the Crosswise MasterChef owner permission.

The attacker:

- called setTrustedForwarder() function to change trustedForwarder

- transferred the ownership

- swapped 0.01 WBNB to 3.71 CRSS through CrosswiseRouter

- deposited 1 CROSS to Crosswise MasterChef

- set strategy to the new one under the hacker's control

- withdrew 692K CRSS from the MasterChef

- swapped 692K CRSS to 547 WBNB

Stolen funds were deposited into the Tornado Cash proxy:

https://explorer.bitquery.io/bsc/txs/calls?caller=0x74834611…fc5089&contract=0x0d5550d5…859b17

Case & protocol details

Classification Other / Access Control
Protocol Type Exploit/Other
Affected asset / contract CRSS
Smart Contract Language Solidity
Official Website www.crosswise.finance/
Protocol Twitter/X @crosswisefi

Evidence & learning

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.