SQ Protocol Hack

Reported loss $346K
Bnb Smart Chain
Improper Access Control

What happened

On May 12, 2026, SQ Protocol on BNB Chain was exploited for approximately $346,137.

Technical root cause

A hardcoded owner backdoor in the verified staking contract enabled an ownership takeover through an authorizationList transaction, permitting the attacker to create and redeem fraudulent staking claims.

How it happened

The attacker took ownership of the staking contract, created false staking claims, redeemed roughly 296,500 USDT, swept SQi tokens, and sold SQi into the SQi/USDT pool for additional proceeds.

Protocol details

Classification Access Control
Protocol Type DeFi Protocol
Implementation language Solidity

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.