iSharesBitcoin Hack
Incident Overview
IBTC token project was rugpulled by the deployer after removing liquidity worth 87,947 USD from PancakeSwap pool.
IBTC is a BEP20 token trading on PancakeSwap. On Oct 26, 2023, the deployer and scammer sent funds from Binance to their addresses. It is assumed that the deployer created the contract in a way that allowed it to be hacked later.
The scammer (0xf4956850…9c5B37) minted a significantly larger number of tokens and then rug pulled by selling 1,000,000,000,000,000 IBTC, completely depleting the liquidity pool. The stolen funds were transferred to another EOA and then distributed between multiple addresses, resulting in a total loss of 87,947 USD worth 394.76 WBNB.
Deployer Address:
https://bscscan.com/address/0xc3295049…918Ed9
Scammers Addresses:
https://bscscan.com/address/0xf4956850…9c5B37
https://bscscan.com/address/0x3f04768E…c704ED
https://bscscan.com/address/0x336dd91C…9ABb11
Token Swap Transaction:
https://bscscan.com/tx/0x8a92789d…da0341
Funds sending from the Binance exchange Transaction:
https://bscscan.com/tx/0xd70007a6…195e94
Incident Report
Protocol Information
Market Context at Time of Hack
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to iSharesBitcoin, these are the critical security checks that could have prevented this incident (October 2023).
- Verify all logic paths related to Rugpull are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
Learn to Prevent the Next iSharesBitcoin
The iSharesBitcoin hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.