Ownly Hack

TOTAL LOST $37K
Low Reentrancy bsc

What happened

Hacker used smart contract vulnerability on OWN Platform Staking to drain all $OWN tokens

Ownly is a NFT platform providing staking opportunity to users. The hacker was able to unstake unlimited times due to a staking contract vulnerability. He created a smart contract which repetitively staked and unstaked, so all remaining $OWN tokens were drained and swapped on SparkSwap and PancakeSwap for the total amount of 19,219 $BUSD.

0x81d3ec77438b4e99aa99ba25b1dbc3fea317fe3b0x81d3ec77438b4e99aa99ba25b1dbc3fea317fe3b

Drainer transaction:

https://bscscan.com/tx/0x2cbe47ed…ea072f

Affected contract address:

https://bscscan.com/address/0x421f3041…9d7e92

Address of attacker:

https://bscscan.com/address/0xba310583…ebd38a

Address of attackers smart contract:

https://bscscan.com/address/0xa81ea095…620386

Case & protocol details

Classification NFT / Protocol Logic
Protocol Type Exploit/Reentrancy
Affected asset / contract OWN
Smart Contract Language Solidity

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.