LayerZero Hack
Incident Overview
LayerZero, a fake BEP20 token, was rugpulled on Aug 20, 2023, causing a loss of 1,045,094 $USD
LayerZero (ZRO) is a copycat BEP20 token trading on PancakeSwap. On Aug 20, 2023, the deployer removed liquidity from the LP pool. The token was advertised on a Russian-speaking Telegram group named KryptoAtom.
The stolen funds, amounting to 1,045,094 $USD worth 4,827.99 $BNB, were transferred through several EOA addresses and then swapped for $USDT. As of August 21, 2023, the funds remain at the scammer's EOA.
- Deployer Address:
https://bscscan.com/address/0x7Ee2fc5e…955aBE
- Scammer Address:
https://bscscan.com/address/0x2ebc576b…b72d5e
- Funds Holder as of August 21, 2023:
https://bscscan.com/address/0xa792a4ad…ad4d84
- Liquidity Removal Transaction:
https://bscscan.com/tx/0x098ed453…2aed67
- Swapping Transactions:
https://bscscan.com/tx/0xefa6247b…1b7352
https://bscscan.com/tx/0x1b63f44b…cf10d2
https://bscscan.com/tx/0x3f49c124…3948ff
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to LayerZero, these are the critical security checks that could have prevented this incident (August 2023).
- Verify all logic paths related to Rugpull are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
Learn to Prevent the Next LayerZero
The LayerZero hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.