FileSystemVideo Hack
What happened
The contract deployer of FSV token invoked addMinter() to grant the external address with the privileged function to mint new tokens:
https://bscscan.com/tx/0x974c0eb7…79cdc6
0x6a6296c4…cf2E43 minted tokens to the 0x746cE483…7C12b3 address.
The stolen funds' recipient was the following address:
https://bscscan.com/address/0x4c64068f…e4b15f#tokentxns
Funds were deposited into Tornado Cash mixer:
https://bscscan.com/tx/0x3fdc3cfc…8c4c9d
https://bscscan.com/tx/0xf5af061f…efb7eb
https://bscscan.com/tx/0x815b2fef…081e40
https://bscscan.com/tx/0x7534b238…79677b
https://bscscan.com/tx/0x6b84ff0b…fa15dd
https://bscscan.com/tx/0x14302cf6…c787b8
https://bscscan.com/tx/0x41156139…9fb17e
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report twitter.com
- report Report twitter.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.