SwapX V2 Hack

Reported loss $1.0M
BNB Chain
Improper Access Control

What happened

On 27 February 2023 a SwapX contract on BNB Chain was abused to drain tokens from users who had approved it. A function with selector 0x4f1f05bc in the unverified implementation contract (0x6D89...1a01) had no proper access control. Anyone could make it spend another user's approved tokens. The attacker used it to push victims' BUSD through a swap into the DND token, then sold DND they already held for WBNB. CertiK counted about $1 million in losses across four attacker EOAs.

PeckShield flagged the attack within hours and asked users to revoke approvals to the SwapX contract. The first exploit transaction was 0x3ee23c1585474eaa4f976313cafbc09461abb781d263547c8397788c68a00160.

Revoke.cash links SwapX to the BSCex exchange, later rebranded LaunchZone. It reports that four old SwapX contracts had the same flaw, that others were drained in the following weeks, and that losses totalled about $7.8 million.

How it happened

  1. Many users had given the SwapX implementation (0x6D89...1a01) BUSD allowances.
  2. Function 0x4f1f05bc took a swap path, an amount and an address to pull tokens from, and did not check that the caller was that address.
  3. For each victim, the attacker called it with path BUSD to WBNB to DND and the victim's full allowance or balance, forcing the victim's BUSD to buy DND and pushing the DND price up.
  4. The attacker then sold DND it held into the inflated pool for WBNB. PeckShield, BlockSec and CertiK all flagged the attack, and CertiK put total losses at about $1M.

Protocol details

Classification Access Control
Protocol Type DeFi Protocol
Implementation language Solidity

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.