Stepp2p Hack

Reported loss $43K
BNB Chain
Unknown

What happened

Stepp2p was a peer-to-peer sale-order contract on BNB Chain that held users' BSC-USD (USDT). It had no visible public presence, and Quadriga Initiative found it was deployed on 7 May 2025. In July 2025 an attacker used a flash loan and a refund bug in its order functions to drain it. TenArmor reported the loss as $43k; Quadriga Initiative's reading of the attack transaction puts it at 43,782.41 BSC-USD. There was no public announcement, and no funds are known to have been recovered.

Attack transaction: 0xe94752783519da14315d47cde34da55496c39546813ef4624c94825e2d69c6a8 Attacker: 0xd7235d08a48cbd3f63b9faa16130f2fdb50b2341

How it happened

  1. The attacker flash-borrowed 50,000 BSC-USD from a PancakeSwap V3 pool.
  2. It opened a sale order with createSaleOrder, depositing an amount equal to the contract's entire BSC-USD balance.
  3. It called cancelSaleOrder on that order, which refunded the deposit.
  4. It then called modifySaleOrder on the same, already cancelled order to reduce it by the full amount. The contract paid out the same amount a second time, even though the order had already been cancelled and refunded.
  5. The attacker repaid the flash loan and kept the second refund, which was the contract's own balance.

Protocol details

Classification Protocol Logic
Protocol Type DeFi Protocol
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.