DarkPool Hack
What happened
Dark Pool token was hacked and 103,859 $USD was stolen from the liquidity pool. The hacker used the vulnerability of the token's smart contract.
Dark Pool is the BEP20 standard token trading on PancakeSwap. The smart contract of the $DPC token has a vulnerability, which allows users to accumulate a huge amount of rewards after staking LP tokens. The claimStakeLP() function was called multiple times by the attacker's malicious contracts and granted the attacker the opportunity to withdraw more than 20,000 $DPC tokens.
Consequently, the attacker swapped $DPC tokens for $USDT and made a profit of 103,859 $USD. All stolen funds remain in the attacker's address at the moment of writing.
Attacker address:
https://bscscan.com/address/0xf211Fa86…5b25C9
Attacker contract:
https://bscscan.com/address/0x2109bbec…4ab419
Draining transaction:
https://bscscan.com/tx/0x92cab23d…72e86f
Liquidity Pool:
https://bscscan.com/address/0x79cd24ed…f04be3
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report en.0xzx.com
- report Report twitter.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.