Levyathan Hack

REPORTED LOSS $1.5M
Medium Private Key Compromised (Stored Publicly) binance bsc

What happened

The Levyathan developers left the private keys to a wallet with minting capability available on Github.

The attacker's address:

https://bscscan.com/address/0x7507f846…9265d3

The minting transaction:

https://bscscan.com/tx/0x86ddfd98…d2135e

The attacker sold tokens at:

https://bscscan.com/tx/0xe3faf5bf…068230

https://bscscan.com/tx/0x06498e85…ddca3f

At this moment the attacker gained ~$122,957

The rest of the tokens were burnt:

https://bscscan.com/tx/0x28934740…5710b0

The attacker exchanged his gains onto ETH at:

https://bscscan.com/tx/0xfba3cd60…87bf2e

https://bscscan.com/tx/0x692d4a6a…ebf3a8

ETH were bridged from BSC to Ethereum Mainnet:

https://etherscan.io/tx/0x7643893e…949166

https://etherscan.io/tx/0x6ee8444d…32877b

Stolen ETH were deposited onto the Tornado Cash mixer at:

https://etherscan.io/tx/0x50a243cf…a0fcca

https://etherscan.io/tx/0xffbabbe3…d53c3f

https://etherscan.io/tx/0xcd715f01…b4f9cb

TVL of the project was $1.5 million, so the total losses are estimated at the same amount.

Case & protocol details

Classification Infrastructure / Other / Frontend & Infrastructure
Protocol Type Exploit/Other
Affected asset / contract LEV
Implementation language Solidity
Official Website www.levyathan.finance/
Protocol Twitter/X @Levyathan_index

Security review history

  • CertiK 2021-05-25 No public report

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.