Poolz Finance Hack
What happened
Poolz Finance was exploited for 443,439 $USD. The hacker exploited overflow vulnerability to receive assets from the project's vault contract.
Poolz Finance is a launchpad running on Binance and Polygon chains. The project was exploited via overflow vulnerability. The LockedDeal vault contract of the platform was exploited, which caused the $POOLZ token price to drop by more than 95%.
The attacker was able to receive various tokens, after draining the vault contract, and exchanged them for 443,439 $USD worth of $BNB. All the stolen funds remain at the attacker's original address at the moment.
Attacker address:
https://bscscan.com/address/0x190cd736…2cef2a
Malicious contract:
https://bscscan.com/address/0x058bae36…1c2203#code
Malicious transaction:
https://bscscan.com/tx/0x4635d5c6…ec45ff
Case & protocol details
Post-Incident Timeline
-
2023-03-16
Poolz Finance announced on their Twitter about restructuring the platform, and the new $POOLX token deployment. The team recommended not to trade the $POOLZ tokens anymore.
Evidence & learning
Sources and on-chain records
- report Report cryptoslate.com
- report Report twitter.com
- report Report twitter.com
- report Report finance.yahoo.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.