Majin Buu Hack
Incident Overview
Majin Buu project was rugpulled by the deployer, removing liquidity worth 168,213 $USD from UniSwap pool.
Majin Buu (BUU) is an ERC20 token trading on UniSwap. The deployer added 38 $ETH as liquidity on July 31 and then removed 129.87 $ETH on August 1. This significant liquidity removal led to a rugpull, with the deployer stealing funds equating to 168,213 $USD at the time of the scam.
The stolen funds were initially transferred to another EOA address and subsequently distributed between several other addresses. The website of the project was shutdown at the moment.
Deployer Address:
https://etherscan.io/address/0x690F2Be8…91132D
Scammer Address:
https://etherscan.io/address/0x6d99a6ac…67666f
Liquidity Removal Transaction:
https://etherscan.io/tx/0xba394684…becf52
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Majin Buu, these are the critical security checks that could have prevented this incident (August 2023).
- Verify all logic paths related to Rugpull are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
- 01
-
02
Web Archive https://archive.ph/5Nly9
Learn to Prevent the Next Majin Buu
The Majin Buu hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.