Local Traders Hack

Reported loss $118K
BNB Chain
Access Control Exploit

What happened

On May 23, 2023, an attacker drained about 380 BNB (roughly $118,000 to $119,000) from Local Traders, a P2P trading project on BNB Smart Chain. The team described it as a breach of its staking pool. One function on the LCT contract let anyone replace the contract owner.

The attacker made themselves owner, used an owner-only function to set the LCT price to 1, bought LCT at that price and sold it for BNB. Local Traders said it was working with security partners on the investigation and a recovery plan. No recovery of funds has been reported.

How it happened

  1. Local Traders sold LCT through a contract whose source was never published. The contract sat behind an upgradeable proxy, and a function on that proxy (selector 0xb5863c10) overwrote the stored owner address without checking who was calling it.
  2. The attacker called 0xb5863c10 and made an address they controlled the owner.
  3. As owner, the attacker called 0x925d400c, which set the stored LCT price to 1, the smallest unit possible.
  4. The attacker called buyTokens() on the LCT exchange contract and bought almost all the LCT it held for a negligible amount of BNB.
  5. The attacker swapped the cheap LCT for WBNB on PancakeSwap and came away with roughly 380 BNB. The attack took four transactions; Beosin's alert cites 0x49a3038622bf6dc3672b1b7366382a2c513d713e06cb7c91ebb8e256ee300dfb.

Protocol details

Classification Protocol Logic / Exchange (DEX) / Access Control
Protocol Type Exploit/Access control
Affected asset / contract LCT
Implementation language Solidity
Protocol links Website @LOCALTRADERSCL

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.