Grizzifi Hack
What happened
Grizzifi, a BNB Chain staking dapp that paid referral and team-milestone bonuses, was exploited on 13 August 2025, a day or two after its 12 August launch. The contract counted a referrer's team milestones based on each downline member's total invested amount, including withdrawn funds, not their active investment. The attacker used about 600 BSC-USD to build a chain of self-controlled referral accounts, qualified them for milestone rewards, and then claimed those rewards with collectRefBonus(). MetaTrust put the loss at about $61,000 in BSC-USD.
The attacker address was 0xe233...af7c, and the bonuses were withdrawn in two transactions, 0xdb5296b1...0058f7 and 0xdb4f2c0d...6bba. No response from the Grizzifi team has been found, and Quadriga reports that the project's website went offline.
How it happened
- The attacker deployed 30 attack contracts and gave each 20 BSC-USD, about 600 BSC-USD in total.
- Each contract approved Grizzifi and called
harvestHoney(0, 10e18, referrer), naming the previous attack contract as its referrer. That built a 30-level referral chain the attacker fully controlled. - Each contract also deployed a helper that invested another 10 BSC-USD under the same referrer, adding more "team members" to each upline.
- Grizzifi's
_incrementUplineTeamCount()checked total invested amounts, including withdrawn funds, not active investments, so these small deposits counted toward team milestones and inflated each account'smilestoneReward. - In two separate withdrawal transactions (
0xdb5296b1...0058f7and0xdb4f2c0d...6bba), the attacker calledcollectRefBonus()on the attack contracts and moved the claimed bonuses back to their address. MetaTrust reported the total loss as about $61K in BSC-USD.
Protocol details
Evidence
- report MetaTrust Alert: Grizzifi contract on BNB Chain attacked, $61K loss (X, via fxtwitter mirror) x.com
- analysis DeFiLlama defillama.com
- analysis DeFiHackLabs Grizzifi_exp.sol PoC raw.githubusercontent.com
- analysis Aug 2025 - GrizziFi milestoneReward Mechanism collectRefBonus Exploit (Quadriga Initiative case study) quadrigainitiative.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.