Gera Coin Hack
Incident Overview
Gera Coin project was hacked through a private key leak. The $GERA token price dumped by over 98% on both Ethereum and BSC DEXes.
Gera Coin is a crypto payment platform. $GERA is a token, which is trading on Ethereum and Binance chains. As said on the official project's Twitter, the private key of the token deployer was leaked, so the hacker was able to transfer ownership to himself, and mint unlimited $GERA tokens. Consequently, the hacker minted 2,179,340,915 ERC20 GERA tokens on the Ethereum network and 275,900,000 GERA BEP20 tokens on the Binance network. The minted tokens were partially sold which led to a token price dumping of more than 98%. The total profit the hacker made is unknown.
Funds lost by chain:
BSC: 119,145 $USD lost and transferred through 1inch
Ethereum: 127,982 $USD lost and bridged through Celer Network
Attacker address:
https://bscscan.com/address/0x510e4d61…8c61dc
Mint transactions:
https://bscscan.com/tx/0x621f7b50…8e9676
https://bscscan.com/tx/0xc80fb935…937eac
Incident Report
Protocol Information
Market Context at Time of Hack
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Gera Coin, these are the critical security checks that could have prevented this incident (September 2022).
- Verify all logic paths related to Other are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
-
01
Source 1 https://archive.is/ZTj5k
Learn to Prevent the Next Gera Coin
The Gera Coin hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.