QAN Platform Hack

REPORTED LOSS $1.2M
Medium Access Control

What happened

QAN Platform Bridge was hacked due to a private key compromise. The hacker gained access to the private key of the bridge deployer address and withdrew $QANX tokens from the bridge contract on both Ethereum and BSC chains.

QAN Platform is the bridge between Ethereum and BSC chains. The hacker compromised the private keys of the bridge contract deployer and withdrew 1,444,000,000 $QANX tokens from the BSC chain and 1,459,000,000 $QANX tokens from the Ethereum chain. Consequently, the attacker swapped $QANX tokens which led to a drop in the token price by more than 99%.

The hacker managed to withdraw 1,165,500 $USD worth of assets through TornadoCash.

Attacker addresses:

https://bscscan.com/address/0xf163a6ca…d4fb11

https://etherscan.io/address/0xf163a6ca…d4fb11

Malicious transactions:

https://bscscan.com/tx/0xf93047e4…a13f51

https://etherscan.io/tx/0x048a1a71…51fe82

https://etherscan.io/tx/0x39ec0a6b…74080f

Case & protocol details

Classification Bridge
Protocol Type Exploit/Access control
Affected asset / contract QANX
Official Website qanplatform.com/en
Protocol Twitter/X @QANplatform

Evidence & learning

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.