Nody Hack
Incident Overview
The $NODY token has been rugpulled by the token creator. The token creator transferred 950M $NODY tokens to a second address (B) under his control. When the price of the token increased, the attacker started selling them, which is why the token began to depreciate.
At the moment of writing ~$104k are on scammer's address (B) of which ~55k are identified as stolen.
The scammer created $NODY token at this transaction: https://bscscan.com/tx/0xde9f9d08…b17998.
After 14 days, 950M $NODY token were sent to intermediary addresses in order to create a fake distribution between token holders and 100M $NODY tokens to the scammer address (C) which created a liquidity pool on PancakeSwap with 50k $BUSD and 50M $NODY. (https://bscscan.com/tx/0xe7e6d523…345b81).
When the people invested their money and the price of the token became acceptable for the scammer, all the intermediary addresses sent tokens to the address of the scammer (B) where, in turn, he began to dump the price by selling assets. Here are the transactions of transferring from intermediary addresses to scammer address (B):
1) https://bscscan.com/tx/0xc4e33358…1947b8
2) https://bscscan.com/tx/0x898e0dad…281125
3) https://bscscan.com/tx/0xcafab31a…848cc5
4) https://bscscan.com/tx/0x1945b09c…034693
Then scammer address (B) swapped $NODY tokens for $BUSD through the 1inch.
Here are example transactions of swap:
1) https://bscscan.com/tx/0x61473eef…f37e49
2) https://bscscan.com/tx/0x11dae52a…1d49c0
3) https://bscscan.com/tx/0xce754bb1…cf49f5
As the time of this writing information on this case is scarce. More sources will be added if the case should develop.
Scammer addresses:
1) https://bscscan.com/address/0xba3e8569…1aff40
2) https://bscscan.com/address/0xde512ea6…3735d2
3) https://bscscan.com/address/0xc45c80c9…09c22f
Intermediary addresses:
1) https://bscscan.com/address/0x1bd55d3c…e95dab
2) https://bscscan.com/address/0xe001a470…45185e
3) https://bscscan.com/address/0x54144148…28987b
4) https://bscscan.com/address/0x893a4926…ba3105
Incident Report
Market Context at Time of Hack
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Nody, these are the critical security checks that could have prevented this incident (July 2022).
- Verify all logic paths related to Rugpull are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
Learn to Prevent the Next Nody
The Nody hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.