EAC Hack
What happened
On August 29, 2023, an attacker made 6,376.85 BSC-USD from the EAC token on BNB Chain. EAC's fund contract exposed a function with no permission check. The function spent the contract's own BSC-USD to buy EAC on PancakeSwap. The attacker used a flash loan to buy EAC first, called that function to push the price up with the project's money, and then sold.
According to Lunaray's analysis, the EAC team later upgraded the proxy to a new logic contract (0x2deb06785a9392c9f7fdc959d429bb0f5774610f) that adds the missing permission check.
How it happened
- The attack contract
0x20dcf125f0563417d257b98a116c3fea4f0b2db2flash-borrowed 300,000 BSC-USD from a DODO pool. - It swapped the loan for EAC on the PancakeSwap V2 pair and received 2,320.81 EAC after EAC's 3% buy fee.
- It called the EAC fund proxy
0xa08a40e0...63561(selector0xe6a24c3f) and passed the contract's own 14,300 BSC-USD balance. That swapped the protocol's funds into EAC, lifting the pool price from about 125 to about 407 BSC-USD per EAC. - It sold its EAC back into the pair (about 2,251 EAC after sell fee, burn and the minimum-hold rule) for 306,376.85 BSC-USD, repaid the 300,000 loan and kept 6,376.85 BSC-USD. Attack tx:
0x477f9ee698ac8ae800ffa012ab52fd8de39b58996245c5e39a4233c1ae5f1baa. Attacker EOA:0x27e981348c2d1f5b2227c182a9d0ed46eed84946.
Protocol details
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.