JohnLennonC0IN Hack
Incident Overview
BEATLES token was rugpulled by scammer, total loss worth more 11,336 USD from PancakeSwap pool.
BEATLES is a BEP20 token trading on PancakeSwap.When the token was created, the token creator sent tokens to three addresses, then a large number of tokens were sold,removed from the LP pool, frome these addresses.The scammers used disperse.app to send funds to multiple addresses, then bought and sold tokens from these addresses , affecting the token price. The deployer did not buy or sell tokens, but both the deployer and scammers received funds from the same address, indicating a scam under the guise of an honest project. Stolen funds were transferred to another EOA and then distributed between multiple addresses.
Deployer Address:
https://bscscan.com/address/0xBAb318f9…b11B9F
Scammer's Addresses:
https://bscscan.com/address/0x861091bE…aa7c4C
https://bscscan.com/address/0x4639026A…833EC8
https://bscscan.com/address/0xefbf0b01…961bcc
Liquidity Add Transaction:
https://bscscan.com/tx/0x22642d3d…1ceb35
Liquidity Removal Transactions:
https://bscscan.com/tx/0xee3bdbc1…8c357a
https://bscscan.com/tx/0x54348d4e…bef544
Transactions where the scammer got the tokens:
https://bscscan.com/tx/0x83f76891…64f472
https://bscscan.com/tx/0x6307aca8…a95b7c
https://bscscan.com/tx/0x2b3bb025…91d6e6
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to JohnLennonC0IN, these are the critical security checks that could have prevented this incident (January 2024).
- Verify all logic paths related to Rugpull are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
Learn to Prevent the Next JohnLennonC0IN
The JohnLennonC0IN hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.