Flare Token Hack
What happened
Flare Token was possibly rugpulled. An EOA address was able to remove funds from the PancakeSwap pool for a total of 17,010,503 $USD after claiming roughly 4,000,000,000 $FLARE tokens from a vault contract.
Flare Token is a BEP20 token trading on PancakeSwap and can't be confused with Flare Network with the $FLR token symbol. An EOA address called a withdrawProfit() function on a contract with an unverified source code and received 3,973,277,600 $FLARE tokens. The part of the claimed tokens was used to perform a swap and drain of liquidity.
The exploiter profited 17,010,503 $USD and transferred funds to another EOA address.
Scammer addresses:
https://bscscan.com/address/0xa0a613ca…53d898
https://bscscan.com/address/0xE55D77F7…68Eb20
Malicious transaction:
https://bscscan.com/tx/0xa0913502…51c027
Liquidity drain transaction:
https://bscscan.com/tx/0x2af9b1c4…1c1d51
Case & protocol details
Post-Incident Timeline
-
2022-11-17
On 17 November, an EOA address that received the funds transferred all the stolen amount through TornadoCash.
Evidence & learning
Sources and on-chain records
- report Report unchainedpodcast.com
- report Report twitter.com
- report Report mobile.twitter.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.