QAN Platform Hack
Incident Overview
QAN Platform Bridge was hacked due to a private key compromise. The hacker gained access to the private key of the bridge deployer address and withdrew $QANX tokens from the bridge contract on both Ethereum and BSC chains.
QAN Platform is the bridge between Ethereum and BSC chains. The hacker compromised the private keys of the bridge contract deployer and withdrew 1,444,000,000 $QANX tokens from the BSC chain and 1,459,000,000 $QANX tokens from the Ethereum chain. Consequently, the attacker swapped $QANX tokens which led to a drop in the token price by more than 99%.
The hacker managed to withdraw 1,165,500 $USD worth of assets through TornadoCash.
Attacker addresses:
https://bscscan.com/address/0xf163a6ca…d4fb11
https://etherscan.io/address/0xf163a6ca…d4fb11
Malicious transactions:
https://bscscan.com/tx/0xf93047e4…a13f51
https://etherscan.io/tx/0x048a1a71…51fe82
https://etherscan.io/tx/0x39ec0a6b…74080f
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to QAN Platform, these are the critical security checks that could have prevented this incident (October 2022).
- Verify all logic paths related to Access Control are guarded by proper access controls and input validation - see the Access Control Attacks attack class for patterns
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSecurity Audit History
- Certik Report
Related Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Sources & References
Learn to Prevent the Next QAN Platform
The QAN Platform hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.