FortuneWheel Hack

TOTAL LOST $21.0M
High Other

What happened

On January 10, 2025, the FortuneWheel smart contract on Binance Smart Chain (BSC) was exploited due to a lack of access control in its swapProfitFees function. This vulnerability allowed an attacker to manipulate token prices and drain nearly $21,000 USD.

The core issue lay in the swapProfitFees function, which was designed to facilitate token swaps through PancakeSwap. However, the function lacked proper access control, allowing anyone to invoke it. The attacker exploited this flaw by first swapping a large amount of WBNB for LINK to manipulate the pool’s price.

They then called the vulnerable function to swap LINK back to WBNB, profiting from the skewed pricing. This sequence of operations enabled the attacker to extract funds from the contract and ultimately caused significant financial losses.

Case & protocol details

Classification Gaming / Metaverse / Gaming / Metaverse / Gaming / Metaverse / Gaming / Metaverse / Gaming / Metaverse / Gaming / Metaverse / Gaming / Metaverse / Gaming / Metaverse / Gaming / Metaverse / Gaming / Metaverse / Gaming / Metaverse / Gaming / Metaverse / Gam
Protocol Type Exploit/Other

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.