StarMan Hack
Incident Overview
The $StarMan token was rugpulled by its team. The team created an StarMan/WBNB pair to make their token tradable and dumped the $StarMan token for a profit of 173.39 $BNB.
The creator of the token deployed the contract to the BNB network, where 10B tokens were sent to him.
Then he created a StarMan/BNB pair, 3B $StarMan and 300 $BNB:
1) https://bscscan.com/tx/0x13c8a4dc…ebc429
2) https://bscscan.com/tx/0x8eff7526…f0b933
After the community invested enough funds into the token, he removed lp, taking a profit of 173 $BNB:
https://bscscan.com/tx/0xe2356bff…57e265
Stolen funds were transferred to scammer address (B): https://bscscan.com/tx/0xfb3fb8ee…f53110
Then the scammer address (B) laundered money through the Tornado.cash.
Involved addresses:
- Scammer address (A), token creator: https://bscscan.com/address/0xcbf5ac38…afaa89
- Scammer address (B): https://bscscan.com/address/0xcffe7b00…64bd44
Transactions:
- Token creation: https://bscscan.com/tx/0x808b6783…9cfb2f
- Creating lp:
1) https://bscscan.com/tx/0x8eff7526…f0b933
2) https://bscscan.com/tx/0x13c8a4dc…ebc429
- Remove lp: https://bscscan.com/tx/0xe2356bff…57e265
Smart-Contract Abilities
- Owner can open trading
- Hidden mechanism for pausing transfers openTrading() for non whitelisted users
- Hidden whitelist roles (_synced)
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to StarMan, these are the critical security checks that could have prevented this incident (June 2022).
- Verify all logic paths related to Rugpull are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSecurity Audit History
- Audit Report 1 Report
Sources & References
Learn to Prevent the Next StarMan
The StarMan hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.