ShadowFi Hack

TOTAL LOST $303K
Low Access Control Attacks bsc

What happened

The ShadowFi project was exploited by a hacker who took advantage of a vulnerability in the $SDF token, making a profit of 1078 $BNB.

ShadowFi is a BEP20 token focused on anonymous payments, NFT, and passive income. The hack proceeds in two parts.

In the first part, the hacker used a scanner to track new token pairs, and stole $WBNB on PancakePair contract.

In the second part, another attacker used the burn function, which mistakenly allows any user to burn $SDF tokens from any address. The attacker burns almost all $SDF tokens on the liquidity pool, so the token price was unfairly high. He deployed an exploit smart contract to use the situation to swap 9 $SDF tokens for 1078 $WBNB and made a profit of 302,817 $USD. Consequently, he swapped all the stolen funds and transferred them to Tornado Cash.

Affected address of token pair:

https://www.bscscan.com/address/0xf9e3151e…ce650a

Address of attacker:

https://bscscan.com/address/0x64785767…492205

Swap transaction:

https://www.bscscan.com/tx/0xe30dc752…a01018

Case & protocol details

Classification Token / Access Control
Protocol Type Exploit/Other
Affected asset / contract SDF
Smart Contract Language Solidity
Official Website shadowfi.com/
Protocol Twitter/X @ShadowFi_

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.