Lucky Star Hack

REPORTED LOSS $297K
Low Access Control

What happened

The Access control issue over the Lucky Star contract led to the approved tokens draining.

A security breach occurred with Lucky Star contracts, where the deployer transferred ownership of the proxy admin to a malicious EOA. This EOA then upgraded to a new implementation with the unverified source code, exploiting users who had previously approved the proxy admin. As a result, approximately $297k worth of LSC and USDT tokens were stolen.

Deployer:

https://bscscan.com/address/0xcde285a5…e4cd01

Transfer ownership:

https://bscscan.com/tx/0xbb2e8abb…7e8d61

Malicious upgrade:

https://bscscan.com/tx/0xb5e79163…8df523

Proxy admin:

https://bscscan.com/address/0x6b2ee199…2b80ca

Proxy contract:

https://bscscan.com/address/0x077e1E0c…E7c9eb#code

Malicious implementation: https://bscscan.com/address/0x32e484A1…4222A9#code

Case & protocol details

Classification Other
Protocol Type Exploit/Access control
Affected asset / contract LCS
Official Website www.lucky-star.fun/

Evidence & learning

Sources and on-chain records

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.