Script Token Hack
Incident Overview
SCPT token rugpulled by the deployer, who removed liquidity worth 133,857 $USD over two days.
SCPT is a BEP20 token trading on PancakeSwap. An investigation revealed that its liquidity pool had been drained after several malicious actions performed by the token's deployer. The attacker used privilege over contracts to modify functions like transferFrom() and remove all available LP funds spread across five transactions within 48 hours.
The total amount of loss due to this attack is approximately 133,857$ USD. Token analysis suggests that it might be a honeypot designed specifically for such an exploit.
Scammer Address:
https://bscscan.com/address/0x77978388…9d5db9
Liquidity removal example:
https://bscscan.com/tx/0x948975f3…903015
Incident Report
Protocol Information
Market Context at Time of Hack
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Script Token, these are the critical security checks that could have prevented this incident (April 2023).
- Verify all logic paths related to Rugpull are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
Learn to Prevent the Next Script Token
The Script Token hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.