MEV Bots Hack

REPORTED LOSS $2.0M
Medium Access Control

What happened

On June 25, 2025, multiple attacks on BNB Chain targeted unidentified, closed-source contracts—likely MEV arbitrage bots—resulting in a combined loss of approximately $2 million. Despite speculation, Venus Protocol was not involved.

Attackers exploited a flaw in the victim contracts’ validation logic, which only checked if the caller was authorized, but failed to restrict what functions could be invoked. This allowed malicious actors to use authorized contracts to directly call sensitive functions and drain assets like vTokens. The attack targeted bots such as printMoney and was executed through a series of crafted calls exploiting poor internal permission handling.

Attack Transaction Tx: 0x7708aaed…131f44

Case & protocol details

Classification Other
Protocol Type Exploit/Access control

Evidence & learning

Sources and on-chain records

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.