GPU Hack

Reported loss $32K
BNB Chain
Arithmetic Error

What happened

On May 8, 2024, the GPU token on BNB Chain was drained for about $32,000 through a self-transfer bug in its balance accounting. When the sender and the recipient of a transfer were the same address, the contract credited the tokens without a matching debit, so every transfer to yourself increased your balance. The attacker bought GPU with borrowed stablecoins, inflated the holding by transferring it to itself repeatedly, and sold the inflated balance back into the PancakeSwap pool. PeckShield reported the GPU price fell about 100% after the attack.

Exploit transaction: 0x2c0ada695a507d7a03f4f308f545c7db4847b2b2c82de79e702d655d8c95dadb. Attacker: 0xcc78063840428c5ae53f3dc6d80759984788cbc0. Attack contract: 0x5234001627a376f5e0accb082548a283b1fa1586.

How it happened

  1. The attacker flash-borrowed stablecoins and swapped them for GPU on PancakeSwap.
  2. It called transfer with its own address as both sender and recipient. The token read the sender and recipient balances into separate cached values, wrote the reduced sender balance, then overwrote the same storage slot with the increased recipient balance. The net effect was a balance increase of amount on every self-transfer.
  3. Repeating the self-transfer compounded the holding. The DeFiHackLabs reproduction transfers the full balance to itself 87 times, doubling it each time.
  4. The attacker sold the inflated GPU back into the pool for stablecoins, repaid the flash loan and kept about $32,000.

Protocol details

Classification Token & Share Accounting
Protocol Type Token
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.