Local Traders Hack
What happened
On May 23, 2023, an attacker drained about 380 BNB (roughly $118,000 to $119,000) from Local Traders, a P2P trading project on BNB Smart Chain. The team described it as a breach of its staking pool. One function on the LCT contract let anyone replace the contract owner.
The attacker made themselves owner, used an owner-only function to set the LCT price to 1, bought LCT at that price and sold it for BNB. Local Traders said it was working with security partners on the investigation and a recovery plan. No recovery of funds has been reported.
How it happened
- Local Traders sold LCT through a contract whose source was never published. The contract sat behind an upgradeable proxy, and a function on that proxy (selector
0xb5863c10) overwrote the stored owner address without checking who was calling it. - The attacker called
0xb5863c10and made an address they controlled the owner. - As owner, the attacker called
0x925d400c, which set the stored LCT price to1, the smallest unit possible. - The attacker called
buyTokens()on the LCT exchange contract and bought almost all the LCT it held for a negligible amount of BNB. - The attacker swapped the cheap LCT for WBNB on PancakeSwap and came away with roughly 380 BNB. The attack took four transactions; Beosin's alert cites
0x49a3038622bf6dc3672b1b7366382a2c513d713e06cb7c91ebb8e256ee300dfb.
Protocol details
Evidence
Proof of concept
1 availableSources
- report Twitter/X Alert twitter.com
- report @BeosinAlert incident report twitter.com
- report @LOCALTRADERSCL incident report twitter.com
- report Beosin Alert on X: Local Traders $LCT exploited for 380 BNB (read via the fxtwitter mirror of the seed tweet) x.com
- report Local Traders on X: Important Announcement: Local Traders Staking Pool Security Incident (read via fxtwitter) x.com
- transaction bscscan.com transaction 0x49a3…0dfb bscscan.com
- transaction bscscan.com transaction 0x57b5…e5ba bscscan.com
- transaction bscscan.com transaction bea605…02ba bscscan.com
- address bscscan.com address 0xd771…6dd7 bscscan.com
- code DeFiHackLabs LocalTrader2_exp.sol PoC (entry: 20230524 Local Trade LCT - Improper Access Control of Close-source contract) github.com
- analysis Website reference neptunemutual.com
- analysis DeFiLlama defillama.com
- analysis Local Traders Hack Analysis — Missing Access Control blog.solidityscan.com
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.