Rabby Wallet Hack
Incident Overview
Rabby Wallet was hacked on multiple chains. The hacker already was able to withdraw 114 $ETH and 179 $BNB through Tornado Cash.
Rabby Wallet is a multichain wallet. The project was hacked within a month after its release. The attacker exploited the user's token approvals and transferred their funds using deployed smart contract.
The total profit of the hacker reached 194,500 $USD at the moment.
Attacker address:
https://bscscan.com/address/0xb6875508…d59d55
Malicious contract:
https://bscscan.com/address/0x48524987…9f059b
Malicious transaction:
https://bscscan.com/tx/0x3d04d662…7ac71c
Incident Report
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Rabby Wallet, these are the critical security checks that could have prevented this incident (October 2022).
- Verify all logic paths related to Other are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSecurity Audit History
- Audit Report 1 Report
Sources & References
Learn to Prevent the Next Rabby Wallet
The Rabby Wallet hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.