RFB Hack
What happened
On December 5, 2022, an attacker exploited the buy lottery in the Roast Football (RFB) token on BNB Chain and took about 12 BNB. RFB gave buyers a chance at a bonus reward, but it picked winners with a pseudorandom number built from values the buyer could know in advance. The attacker bought only when the draw would win and reverted every other attempt. BlockSec flagged the attack; SolidityScan reports two wins in about fifty tries.
Attack transaction: 0xcc8fdb3c6af8bb9dfd87e913b743a13bbf138a143c27e0f387037887d28e3c7a.
How it happened
- The attacker took a 20 WBNB flash loan from a DODO pool and unwrapped it to BNB.
- In a loop of about 50 attempts, the attack contract bought RFB with BNB through PancakeSwap and immediately sold the RFB back for BNB.
- After each buy-and-sell, it checked whether its BNB balance had grown. If not, it reverted that attempt, so a losing draw cost only gas.
- Buys that won the lottery paid out the bonus reward and were kept.
- The attacker repaid the flash loan and kept about 12 BNB.
Protocol details
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.