RES Token Hack

Reported loss $290K
BNB Chain
Spot Price Manipulation

What happened

On 6 October 2022 an attacker made about $290,671 from the RES token on BNB Chain in a flash-loan price-manipulation attack. The RES contract had an external function, thisAToB(), that anyone could call. It swapped the RES held by the contract into the linked ALL token along a RES-USDT-ALL path. BlockSec named this callable function as the root cause.

The attacker ran the attack in two transactions, making about $209K and then about $81K. RES fell about 97%, from roughly $0.23 to $0.006. According to QuillAudits, the attacker swapped the proceeds into BUSD, BNB and other tokens and moved them to another contract. No recovery was reported.

How it happened

  1. The attacker funded their wallet (0x986b2e2a1cf303536138d8aC762447500Fd781c6) with 0.5 BNB and deployed an attack contract (0xff333de02129af88aae101ab777d3f5d709fec6f).
  2. They flash-borrowed USDT from PancakeSwap and made a series of buys from the USDT/RES pair, sending the RES to an externally owned address because RES does not allow transfers to contracts. These buys also earned ALL token rewards.
  3. They called the public thisAToB(), which made the RES contract swap its own RES through the pool. This shifted the pool's reserve ratio in the attacker's favour.
  4. They sold the ALL tokens for USDT and then sold the RES back into the manipulated USDT/RES pair for more USDT than they had paid.
  5. They repaid the flash loan and repeated the process in a second transaction (0xe59fa482...ba96d, then 0xef19a4df...609ac), for about $290K in total.

Protocol details

Classification Oracle Manipulation
Protocol Type DeFi Protocol
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.