Sport Move Hack
Incident Overview
Sport Move confirmed that it was running away, and $SPORT fell by more than 61%. The project froze and deleted its social accounts about 10 hours after launch. In total, 507 BNB was laundered through Tornado Cache
Token contract: https://bscscan.com/address/0x25443319…AFd300
Marketing pool : https://bscscan.com/address/0x2f422C25aA425ECE9f0e0E85baA149d586517bd
From marketing pool address were totally transferred 507 BNB:
https://bscscan.com/tx/0x7b31b900…52cb63
https://bscscan.com/tx/0x2cee84aa…6055b8
https://bscscan.com/tx/0xbd0d9408…01bd2c
https://bscscan.com/tx/0xa8dd9031…5c3269
https://bscscan.com/tx/0x91e9ef13…c90d00
https://bscscan.com/tx/0x17ea545e…62dbaa
Then tokens were laundered via Tornado Cache:
https://bscscan.com/address/0xf4e796BB…18cae1
https://bscscan.com/tx/0xc8701ebb…4289c5 -> 100BNB
https://bscscan.com/address/0xeC70A137…e6B867
https://bscscan.com/tx/0xcb2909c9…2b5dcf -> 100BNB
https://bscscan.com/address/0x3d0bC563…BF0c15
https://bscscan.com/tx/0x533c6151…4f88b2 -> 100BNB
https://bscscan.com/address/0x9B64930e…4C40bF
https://bscscan.com/tx/0xd97ee4af…cf7476 -> 100BNB
https://bscscan.com/tx/0xc49bc29c…0f436b -> 100BNB
https://bscscan.com/address/0xFD679488…eC5DfA
https://bscscan.com/tx/0xb3a30166…a45d08 -> 1BNB
https://bscscan.com/tx/0xdae7a2bb…d71dd5 -> 1BNB
https://bscscan.com/tx/0x87cec42b…678ada -> 1BNB
https://bscscan.com/tx/0x35b7e293…9aae89 -> 1BNB
https://bscscan.com/tx/0x9bd8dafe…3570c8 -> 1BNB
https://bscscan.com/tx/0x173db020…c79af2 -> 1BNB
https://bscscan.com/tx/0x434fd339…9a76d4 -> 1BNB
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Sport Move, these are the critical security checks that could have prevented this incident (May 2022).
- Verify all logic paths related to Rugpull are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
-
01
Source 1 https://twitter.com/sportmove_
- 02
Learn to Prevent the Next Sport Move
The Sport Move hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.