MIKE and SID Tokens Hack
Incident Overview
MIKE and SID tokens suffered from a rugpull, performed by the same EOA, causing a loss of 169,652 $USD.
Two ERC20 tokens, MIKE and SID, experienced a rugpull from an EOA address connected with both token deployers. The perpetrator utilized a backdoor function to mint and swap a large amount of tokens. The MIKE/WETH pool was drained for 50.44 $ETH, worth around 98,095 $USD, and the SID/WETH pool was drained for 37.38 $ETH, worth approximately 71,557 $USD at the time of the incident.
All the stolen funds were transferred to two EOA addresses.
Scammer Address:
https://etherscan.io/address/0xF7E0d995…28F79D
Liquidity Drain Transactions:
https://etherscan.io/tx/0xc70c66d1…977e63
https://etherscan.io/tx/0x4047eb8b…aabb30
Funds Transfer Transactions:
https://etherscan.io/tx/0xbdd481c5…7593ae
https://etherscan.io/tx/0x3889e410…329c1e
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to MIKE and SID Tokens, these are the critical security checks that could have prevented this incident (July 2023).
- Verify all logic paths related to Rugpull are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
Learn to Prevent the Next MIKE and SID Tokens
The MIKE and SID Tokens hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.