Lympo Hack

REPORTED LOSS $18.7M
High Unauthorized transfers from compromised project wallets Ethereum BNB Chain

What happened

On January 10, 2022, attackers accessed Lympo's operational hot wallet(s) and transferred approximately 165.2 million LMT, valued at about $18.7 million at the time. Lympo said cold reserves were unaffected, took liquidity-protection measures, and later announced a token-remediation plan for holders. The public record does not establish how the wallet access was obtained or confirm that the stolen tokens were recovered.

Case & protocol details

Classification Operational hot-wallet compromise; entry path publicly undisclosed
Protocol Type Gaming
Affected asset / contract LMT
Official Website nft.lympo.io/
Protocol Twitter/X @Lympo_io

How it happened

The incident involved compromised operational hot-wallet access rather than a disclosed smart-contract flaw. Lympo identified ten affected project wallets across its Ethereum and BNB Smart Chain activity and said the attacker transferred LMT from them. The team removed LMT liquidity to reduce price disruption and later offered token replacement for eligible holders.

That remediation concerned holders and is not evidence that the stolen LMT was recovered.

Security review history

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.