PARALUNI Hack

TOTAL LOST $1.7M
Medium Other

What happened

The exploiter:

https://bscscan.com/address/0x94bc1d55…5fcf8f

The example transaction behind the exploit:

https://bscscan.com/tx/0x70f367b9…b7ad54

The hack is made possible due to a reentrancy bug (introduced by the use of a crafted token contract) in the depositByAddLiquidity() function, which somehow doubles the credits the hacker is able to claim. The result gains were swapped via PancakeSwap.

Stolen funds were bridged via cBridge and deposited into Tornado Cash mixer:

https://etherscan.io/address/0x94bc1d55…5fcf8f

Case & protocol details

Classification Exchange (DEX)
Protocol Type DEX
Official Website paraluni.org/
Protocol Twitter/X @paraluni

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.