LaunchZone Hack

Reported loss $700K
BNB Chain
Access Control Exploit

What happened

On February 27, 2023, LaunchZone’s BNB Chain liquidity was attacked through a legacy BSCex SwapX implementation. The attacker exploited an unrestricted swap path to act against an address that had given the implementation very large LZ and BUSD allowances, then used the resulting trades to crash LZ’s price and extract BUSD. Verichains traced nearly 88,000 BUSD in the analyzed transaction; broader incident reporting estimated LaunchZone’s liquidity loss at about $700,000.

How it happened

  1. The LZ deployer wallet had previously granted a SwapX implementation large LZ and BUSD allowances.
  2. The attacker invoked its unrestricted swap function with data that made it transfer tokens from the approved deployer address rather than from the caller.
  3. The forced trades dumped LZ and distorted its price; the attacker then bought a large amount of LZ back cheaply.
  4. The attacker sold those tokens on PancakeSwap and took nearly 88,000 BUSD in the transaction traced by Verichains. This transaction-specific amount should not be confused with broader incident-loss estimates.

Protocol details

Classification Protocol Logic / Exchange (DEX) / Token / Access Control
Protocol Type Exploit/Other
Affected asset / contract LZ
Implementation language Solidity
Protocol links Website @launchzoneann

Post-Incident Timeline

  • 2023-03-07

    The LaunchZone Team announced their compensation program to users. The program is implemented via vesting, and affected users will be paid in $iRD tokens that have 15 month vesting period. The token can be exchanged for $RD for transactions and the $iRD itself can be staked to get rewards in $USDC, said in official Twitter

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.