DMC Token Hack
Incident Overview
At the inception of the project 520m DMC tokens were minted. The scammer received 100m DMC by the contract deployer. The scammer waited 25 days for the project to accrual value before he started dumping the DMC tokens and extracting nearly 500k $BUSD in ill-gotten gains in the process.
The 520m DMC tokens were minted to the deployer's address, which were sent to an intermediary address. Part of the tokens were sent to scammer addresses for creating a pair on PancakeSwap. When the price reached a certain value, the address (B) that had a huge amount of tokens sent 390m DMC to the address (C) that started dumping the price.
As the time of this writing information on this case is scarce. More sources will be added if the case should develop.
Token minting to contract deployer: https://bscscan.com/tx/0x2ee4aabe…5c1de5
Transferring total supply to address (B): https://bscscan.com/tx/0x73dcbb2c…f653d2
Transferring 390m DMC tokens to (C): https://bscscan.com/tx/0xc585157b…a47a3c
Transferring 100m tokens to address (D): https://bscscan.com/address/0x3f9a3e5e…5bf772
Example transactions of scammer dumping tokens on Pancake Swap.
1 https://bscscan.com/tx/0x7abcebdb…ff1712
2) https://bscscan.com/tx/0x3bc3d314…611954
3) https://bscscan.com/tx/0x4cf32944…b55c36
Scammer addresses:
1) https://bscscan.com/address/0x094f8627…2923e2
2) https://bscscan.com/address/0xbdb67e30…fb081e
3) https://bscscan.com/address/0x7fa859c9…7650ec
Involved addresses:
https://bscscan.com/address/0x3f9a3e5e…5bf772
https://bscscan.com/address/0xb72d20ea…d82ad8
Scammer smart-contracts:
https://bscscan.com/address/0xde8e87b2…7e7c0e
https://bscscan.com/address/0xeb58734f…49c770
Incident Report
Protocol Information
Market Context at Time of Hack
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to DMC Token, these are the critical security checks that could have prevented this incident (June 2022).
- Verify all logic paths related to Rugpull are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialLearn to Prevent the Next DMC Token
The DMC Token hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.