Proxy_b7e1 Hack

Reported loss $8K
BNB Chain
Unknown

What happened

On November 24, 2024 an unnamed order/escrow contract behind the proxy 0xb7E1...63C6 on BNB Chain lost its whole USDT balance, about $8.5K. TenArmor flagged the attack. The contract's logic is in an unverified implementation, so its behaviour is known only from the attack trace.

The trace shows one multi-purpose function (selector 0x9b3e9b92) that both created orders and settled them. Anyone could call it. It accepted a caller-chosen order payload and caller-supplied payout amounts, and it did not check that a referenced order had been funded or that the caller was owed anything. The attacker created an order without depositing anything, then settled it for the contract's full 8,484.92 USDT and swapped the USDT for about 13 BNB.

Attack tx: 0x864d33d006e5c39c9ee8b35be5ae05a2013e556be3e078e2881b0cc6281bb265 Attacker: 0x9f2eceC0145242c094b17807f299Ce552A625ac5

How it happened

  1. The attacker's contract read the proxy's USDT balance (8,484.92 USDT).
  2. It called 0x9b3e9b92 with an attacker-chosen payload and empty order and amount arrays. This created a new order without any USDT being deposited.
  3. It called 0x9b3e9b92 again, referencing the new order ID (read from nextOrderId()) with the proxy's full USDT balance as the amount. The contract sent all 8,484.92 USDT to the attacker and also minted receipt tokens to them.
  4. The attacker swapped the USDT for about 13.04 BNB on PancakeSwap and sent it to their EOA.

Protocol details

Classification Protocol Logic
Protocol Type DeFi Protocol
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.