NFTG Hack

Reported loss $10K
BNB Chain
Improper Access Control

What happened

On November 26, 2024 the NFTG presale contract on BNB Chain lost about $10K in USDT. TenArmor reported that its PresaleWithUSDT function let a buyer get back more USDT than they deposited. According to a replay of the attack trace, each call charged 76.5 USDT and paid out about 989.64 USDT from the presale's own balance, so repeating it drained the contract from about 10,055 USDT to about 10.7 USDT.

The presale contract's source is not verified on BscScan, so the exact bug in its pricing code is not confirmed. The trace analysis reports that the function reads the Chainlink BNB/USD feed and suggests the payout was scaled by a BNB price while the charge was a flat USDT amount. The attacker left an on-chain message to the NFTG deployer claiming the exploit was a whitehat interception. No report of the funds being returned was found.

Attack tx: 0xbd330fd17d0f825042474843a223547132a49abb0746a7e762a0b15cf4bd28f6 Attacker: 0x5af00B07a55F55775e4d99249DC7d81F5bc14c22

How it happened

  1. The attacker's contract took a zero-fee flash loan of about 825.56 USDT from a DODO DPP pool as working capital and approved the presale contract to spend its USDT.
  2. Inside the callback it called PresaleWithUSDT (selector 0x85d07203) 11 times with itself as recipient.
  3. Each call pulled 76.5 USDT from the attacker and sent back about 989.64 USDT from the presale's balance, a gain of about 913 USDT per call.
  4. The attacker repaid the flash loan and moved the remaining 10,044.49 USDT to their EOA.

Protocol details

Classification Access Control
Protocol Type DeFi Protocol
Implementation language Solidity

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.