GYM Network Hack

Reported loss $1K
BNB Chain
Improper Access Control

What happened

On July 31, 2023, an attacker used a flaw in GYM Network's GymRouter on BNB Chain to force-sell other users' GYMNET tokens. The router's fee-on-transfer swap functions pulled input tokens from the to address (the swap recipient) instead of from msg.sender (the caller). Many GYM users had already approved GymRouter to spend their GYMNET, so anyone could name a victim as the recipient and sell that victim's whole balance.

The attacker routed these forced sells into a pool it controlled alone. It emptied 18 holders' balances, about 151k GYMNET in total, and netted about 117,193.51 GYMNET after repaying its flash loan. DeFiHackLabs marks the USD loss as unclear.

How it happened

  1. The attacker contract flash-borrowed 1,010,000 GYMNET from an existing PancakeSwap GYMNET pair.
  2. It added the borrowed GYMNET and a large amount of fakeUSDT, a token it had deployed itself, to a new GYMNET/fakeUSDT PancakeSwap pool, making itself the only LP.
  3. For each of 18 victims who had approved GymRouter, it called swapExactTokensForTokensSupportingFeeOnTransferTokens with the victim's full GYMNET balance, path GYMNET to fakeUSDT, and to set to the victim. The router took the GYMNET from the victim and paid the victim in near-worthless fakeUSDT.
  4. The victims' GYMNET built up in the attacker's pool. The attacker removed all the liquidity, getting back its 1,010,000 GYMNET plus the victims' tokens.
  5. It repaid the flash loan (1,043,936 GYMNET including the fee) and kept about 117,193.51 GYMNET.

Protocol details

Classification Access Control
Protocol Type DeFi Protocol
Implementation language Solidity

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.