RETAWATCH Hack
Incident Overview
The $RTW token has been rugpulled by the contract creator. The contract creator sent 15M $RTW to the scammer address (B) who created a liquidity pool between $BNB and $BUSD. When the price of the token appreciated, the scammer took profits.
The contract creator deployed the contract to the network and verified its source code. Then he sent 15M $RTW tokens to scammer address (B), which created a liquidity pool between tokens such as $BNB and $BUSD. In total, the value of the pool was approximately $16.8K.
Liquidity creation with $BUSD: https://bscscan.com/tx/0x1b7df886…d351b9
Liquidity creations with $BNB: https://bscscan.com/tx/0xab1311a6…4c516b
After the pool was created, the deployer began distributing tokens between accounts artificially created by the team that took up this project to create a fake distribution of tokens between accounts, here is an example addresses:
1) https://bscscan.com/address/0xf04fc8f7…0007c4
2) https://bscscan.com/address/0x1232ca2e…f9929e
3) https://bscscan.com/address/0xfccd8eff…b95dfe
Scammer address (B) removed the liquidity several times, taking profit, of $3.7K.
Remove liquidity transactions:
1) https://bscscan.com/tx/0x219bae11…693543
2) https://bscscan.com/tx/0x9c0b9854…9700df
3) https://bscscan.com/tx/0x1132159c…b2edad
The contract creator then sent 20M tokens to scammer address (C) in this transaction:
https://bscscan.com/tx/0x1f61d921…20bb76
The tokens received by scammer address(C) were exchanged for 96.5 $BNB via PancakeSwap:
https://bscscan.com/address/0xd18e87e3…38322a
Then 25 $BNB was sent to scammer address (D) in this transaction:
https://bscscan.com/tx/0x7bdcb62b…291711
Scammer addresses (E) and (F) swapped tokens for BUSD:
Scammer address (E) transaction: https://bscscan.com/tx/0x78f78503…893fd9
Scammer address (F) transaction: https://bscscan.com/tx/0xf7b329e7…d68337
Scammer account addresses:
1) https://bscscan.com/address/0x94ba9057…3f5a5a
2) https://bscscan.com/address/0xd18e87e3…38322a
3) https://bscscan.com/address/0xc39e6417…120d75
4) https://bscscan.com/address/0xf5d2e7d1…a653ef
5) https://bscscan.com/address/0xbf0b5acc…395dcb
6) https://bscscan.com/address/0x829d2235…be5f1f
Contract creation transaction: https://bscscan.com/tx/0x84abb3f0…969709
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to RETAWATCH, these are the critical security checks that could have prevented this incident (July 2022).
- Verify all logic paths related to Rugpull are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
Learn to Prevent the Next RETAWATCH
The RETAWATCH hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.