RedRubyDAO Hack
What happened
RedRubyDAO project was exploited, the attacker used a smart contract deployment to receive 85,000,000 tokens and sold them in the same transaction.
RRD is a BEP20 token of the RedRubyDAO project. The liquidity pool of the token is located on the W3Swap. The hacker deployed a malicious smart contract and transferred 85,000,000 $RRD tokens to the contract balance.
Consequently, the hacker swapped 83,300,000 $RRD on W3swap and received 91,000 $BUSD in the same transaction. The remaining $RRD tokens were transferred to two EOA addresses. The stolen funds stay in the hacker's address at the moment.
Attacker address:
https://bscscan.com/address/0x9a52daeb…7b18ad
Malicious contract:
https://bscscan.com/address/0x771f25e7…59d9a8
Malicious transaction:
https://bscscan.com/tx/0x0bb6b1e4…bea209
Liquidity pool:
https://bscscan.com/address/0xd577a5c1…2c8864
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report twitter.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.