CryptoBottle Hack
What happened
In October 2024, CryptoBottle on Polygon was exploited three times, resulting in total losses of approximately $527k.
The Navigator’s Adventage contract allowed users to acquire NAS tokens through minting or swapping, controlled by the fixedPriceEnabled variable. However, public functions permitted anyone to toggle this variable. The attacker set fixedPriceEnabled to true, enabling the mint function and disabling the balance check in swap(). They conducted swaps where 1 USDT was exchanged for millions of NAS tokens. After accumulating NAS, they toggled fixedPriceEnabled back to false, sold the tokens, and drained the USDT liquidity.
The attacker ultimately transferred 493,652 USDT to a wallet linked to a prior CryptoBottle exploit on October 22. The funds remain in that wallet at the time of reporting.
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report certik.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.