GPU Hack
What happened
On May 8, 2024, the GPU token on BNB Chain was drained for about $32,000 through a self-transfer bug in its balance accounting. When the sender and the recipient of a transfer were the same address, the contract credited the tokens without a matching debit, so every transfer to yourself increased your balance. The attacker bought GPU with borrowed stablecoins, inflated the holding by transferring it to itself repeatedly, and sold the inflated balance back into the PancakeSwap pool. PeckShield reported the GPU price fell about 100% after the attack.
Exploit transaction: 0x2c0ada695a507d7a03f4f308f545c7db4847b2b2c82de79e702d655d8c95dadb. Attacker: 0xcc78063840428c5ae53f3dc6d80759984788cbc0. Attack contract: 0x5234001627a376f5e0accb082548a283b1fa1586.
How it happened
- The attacker flash-borrowed stablecoins and swapped them for GPU on PancakeSwap.
- It called
transferwith its own address as both sender and recipient. The token read the sender and recipient balances into separate cached values, wrote the reduced sender balance, then overwrote the same storage slot with the increased recipient balance. The net effect was a balance increase ofamounton every self-transfer. - Repeating the self-transfer compounded the holding. The DeFiHackLabs reproduction transfers the full balance to itself 87 times, doubling it each time.
- The attacker sold the inflated GPU back into the pool for stablecoins, repaid the flash loan and kept about $32,000.
Protocol details
Evidence
- report PeckShieldAlert: $GPU has been exploited for ~$32K twitter.com
- analysis DeFiLlama defillama.com
- analysis GPU Hack Analysis (SolidityScan) blog.solidityscan.com
- analysis The Hidden Danger of Self-Transfers in ERC20 Contracts (Verichains) blog.verichains.io
- analysis DeFiHackLabs GPU_exp.sol raw.githubusercontent.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.