Proxy_b7e1 Hack
What happened
On November 24, 2024 an unnamed order/escrow contract behind the proxy 0xb7E1...63C6 on BNB Chain lost its whole USDT balance, about $8.5K. TenArmor flagged the attack. The contract's logic is in an unverified implementation, so its behaviour is known only from the attack trace.
The trace shows one multi-purpose function (selector 0x9b3e9b92) that both created orders and settled them. Anyone could call it. It accepted a caller-chosen order payload and caller-supplied payout amounts, and it did not check that a referenced order had been funded or that the caller was owed anything. The attacker created an order without depositing anything, then settled it for the contract's full 8,484.92 USDT and swapped the USDT for about 13 BNB.
Attack tx: 0x864d33d006e5c39c9ee8b35be5ae05a2013e556be3e078e2881b0cc6281bb265
Attacker: 0x9f2eceC0145242c094b17807f299Ce552A625ac5
How it happened
- The attacker's contract read the proxy's USDT balance (8,484.92 USDT).
- It called
0x9b3e9b92with an attacker-chosen payload and empty order and amount arrays. This created a new order without any USDT being deposited. - It called
0x9b3e9b92again, referencing the new order ID (read fromnextOrderId()) with the proxy's full USDT balance as the amount. The contract sent all 8,484.92 USDT to the attacker and also minted receipt tokens to them. - The attacker swapped the USDT for about 13.04 BNB on PancakeSwap and sent it to their EOA.
Protocol details
Evidence
- analysis DeFiLlama defillama.com
- analysis TenArmor Security Alert on proxy 0xb7e1 (X status 1860867560885150050, via fxtwitter) api.fxtwitter.com
- analysis DeFiHackLabs PoC proxy_b7e1_exp.sol raw.githubusercontent.com
- analysis ERC1967Proxy (0xb7E1...) Exploit - Unauthenticated Order Settlement Drains Proxy Reserves (Crypto Training) crypto.training
- analysis BscScan block 44294726 bscscan.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.