Melody Hack

REPORTED LOSS $644K
Low Access Control

What happened

Melody project was exploited for 2225 $BNB. The hacker was able to withdraw $SNS tokens using an off-chain vulnerability.

Melody is a GameFi and SocialFi project providing passive income opportunities to creative people. The project's signature check function was exploited by the attacker, which gained $SNS tokens and swapped them for 2225 $BNB. All the stolen amount was sent to another EOA address.

Attacker addresses:

https://bscscan.com/address/0xa3793ccb…7e43a0

https://bscscan.com/address/0x7ce402b6…25408a

https://bscscan.com/address/0x1e091ae0…cebdb7

Malicious transactions:

https://bscscan.com/tx/0x7fd61155…9dea8f

https://bscscan.com/tx/0xe10c76cb…b59e83

Case & protocol details

Classification Gaming / Metaverse
Protocol Type Exploit/Access control
Affected asset / contract SGS
Official Website www.ammelody.com/
Protocol Twitter/X @Melody_SGS

Evidence & learning

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.