MinterPro Hack
Incident Overview
The contract deployer added initial liquidity multiple times, the example transactions:
https://www.bscscan.com/tx/0x54a8d82b…16bc8c
https://www.bscscan.com/tx/0xc80a76fa…9aa0fe
The contract deployer invoked mint() function to generate new tokens onto his wallet multiple times, the example transactions:
https://www.bscscan.com/tx/0xc6e84ded…9f1685
https://www.bscscan.com/tx/0xf893cc5b…ff93df
https://www.bscscan.com/tx/0x5468bd8c…9af91f
The minted tokens were sold multiple times by the contract deployer:
https://www.bscscan.com/tokentxns?a=0x7f659509…a3c981&p=2
The liquidity was removed multiple times as well, the example transaction:
https://www.bscscan.com/tx/0x35ce29dc…4ba660
The stolen funds were bridged to the Binance Chain via BSC: Token Hub by the contract deployer at:
https://www.bscscan.com/tx/0x65b0f544…71ecf4
https://www.bscscan.com/tx/0x1dc038a8…4c86e3
https://www.bscscan.com/tx/0x0d6dbde0…0a370a
https://www.bscscan.com/tx/0xd88dcf0c…071d97
https://www.bscscan.com/tx/0x4b9e5893…f0c76c
https://www.bscscan.com/tx/0x83d2edfb…092d06
https://www.bscscan.com/tx/0xf2e467f2…78e955
https://www.bscscan.com/tx/0x7e25ad9d…a10de0
https://www.bscscan.com/tx/0xb3676b60…f552fd
https://www.bscscan.com/tx/0x2c578e10…bf3eca
https://www.bscscan.com/tx/0x2255b828…a1f800
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to MinterPro, these are the critical security checks that could have prevented this incident (January 2021).
- Verify all logic paths related to Rugpull are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
-
01
Source 1 https://minterpro.vip/
- 02
Learn to Prevent the Next MinterPro
The MinterPro hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.