PancakeSwap Hack

TOTAL LOST $1.8M
Medium Access Control Attacks bsc

What happened

Since April 12th, 2021 a person who had access to a Binance Smart Chain account 0x35f16a46…4095a1 (PancakeSwap admin account) has stolen from PancakeSwap lottery pool 59,765 Cakes (equivalent of about $1,800,000). He used the exploit a few times. Shortly after the last theft, the lottery game was suspended, and this account was banned by PancakeSwap.

The admin of PancakeSwap used his opportunity to manually call lottery contract methods such as:

- function drawing(uint256 _externalRandomNumber) external onlyAdmin

- function enterDrawingPhase() external onlyAdmin

He executed a few calls simultaneously (buy, enter drawing, draw) and put them all into the same block. That created for him an opportunity to predict jackpot numbers, since the random number generator, based on the previous block hash, was no longer random.

Case & protocol details

Classification Exchange (DEX) / Access Control
Protocol Type Exploit/Other
Affected asset / contract CAKE
Smart Contract Language Solidity
Official Website pancakeswap.finance/
Protocol Twitter/X @PancakeSwap

Evidence & learning

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.