Stepp2p Hack
What happened
Stepp2p was a peer-to-peer sale-order contract on BNB Chain that held users' BSC-USD (USDT). It had no visible public presence, and Quadriga Initiative found it was deployed on 7 May 2025. In July 2025 an attacker used a flash loan and a refund bug in its order functions to drain it. TenArmor reported the loss as $43k; Quadriga Initiative's reading of the attack transaction puts it at 43,782.41 BSC-USD. There was no public announcement, and no funds are known to have been recovered.
Attack transaction: 0xe94752783519da14315d47cde34da55496c39546813ef4624c94825e2d69c6a8
Attacker: 0xd7235d08a48cbd3f63b9faa16130f2fdb50b2341
How it happened
- The attacker flash-borrowed 50,000 BSC-USD from a PancakeSwap V3 pool.
- It opened a sale order with
createSaleOrder, depositing an amount equal to the contract's entire BSC-USD balance. - It called
cancelSaleOrderon that order, which refunded the deposit. - It then called
modifySaleOrderon the same, already cancelled order to reduce it by the full amount. The contract paid out the same amount a second time, even though the order had already been cancelled and refunded. - The attacker repaid the flash loan and kept the second refund, which was the contract's own balance.
Protocol details
Evidence
- report TenArmor Security Alert (X post, via fxtwitter mirror) x.com
- code DeFiHackLabs Stepp2p_exp.sol github.com
- code DeFiHackLabs past/2025 README: 20250720 Stepp2p - Logic Flaw github.com
- analysis DeFiLlama defillama.com
- analysis Stepp2p Binance Smart Chain Smart Contract Exploit Drain - $44k (Quadriga Initiative) quadrigainitiative.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.