FFIST Hack

Reported loss $110K
BNB Chain
Reward Logic Flaw

What happened

On July 20, 2023, attackers drained the liquidity pools of FFIST and several similar tokens on BNB Smart Chain, for losses of about $110K. FFIST's transfer logic included an _airdrop() routine that sent tokens to pseudo-randomly generated addresses. The address was derived from inputs a caller can predict and control: the last airdrop address, the block number and the transfer's from/to addresses. The attacker could therefore pick a transfer that made the airdrop target the FFIST/USDT pair itself, reset the pair's FFIST balance to 1, and then buy the pool's USDT with a tiny amount of FFIST.

BlockSec Phalcon put the ~$110K figure as the total across a series of similar tokens. SolidityScan attributes about $110K to FFIST.

How it happened

  1. The attacker (0xcc8617331849962c27f91859578dc91922f6f050) bought a small amount of FFIST with WBNB through PancakeSwap.
  2. It computed a recipient address that, combined with lastAirdropAddress(), the current block number and the sender, would make _airdrop() produce the FFIST/USDT pair's address.
  3. It sent a 0 FFIST transfer to that recipient. The transfer hook's airdrop then hit the pair and, per Phalcon, set the pair's FFIST balance to 1.
  4. It called sync() on the pair so the reserve matched the collapsed FFIST balance, which made FFIST extremely expensive in USDT terms.
  5. It sold its FFIST back through the pair for the pool's USDT and converted to WBNB (tx 0x199c4b88...9f0e0).

Protocol details

Classification Protocol Logic
Protocol Type Token
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.