StableMagnet Hack
What happened
StableMagnet was rugpulled for over 27,000,000 $USD. The scammer used an unverified contract to transfer approved tokens.
The exit scam started from this transaction:
https://bscscan.com/tx/0xf0ba46c8…5d967c
As a result, 8M USDT, 7.2M USDC, and 7M BUSD were taken from the StableMagnet 3Pool via an unverified source code.
The unverified SwapUtil library did not only contain code to drain all pairs, it also contained code to transfer more tokens to everyone who had approved StableMagnet.
SwapUtils library containing the exploit:
https://bscscan.com/address/0xE25d0577…3eaA9a
The stolen funds were distributed between some external wallets. BUSD sent to Binance hot wallet:
https://bscscan.com/address/0x2bac0445…fb96d7#tokentxns
Tether received on ETH chain:
https://etherscan.io/address/0xDF5B180c…bDEF26#tokentxns
Tether changed to DAI:
https://etherscan.io/address/0xe5daac90…912a07#tokentxns
Case & protocol details
Funds Recovery
Recovered
$24.0M
Net Loss
$2,997,000
Post-Incident Timeline
-
2022-12-01
On 1 December 2022, after a year after the incident, 24,000,000 $USD from the stolen assets were returned.
Evidence & learning
Sources and on-chain records
- report Report twitter.com
- report Post-mortem rekt.news
- analysis Web Archive web.archive.org
- analysis Website reference twitter.com
- analysis Website reference twitter.com
- analysis Website reference twitter.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.