TECRA Hack

TOTAL LOST $643K
Low Other

What happened

The exploiter's address:

https://etherscan.io/address/0xb19b7f59…e9c299

The transaction behind the exploit:

https://etherscan.io/tx/0x81e9918e…631154

The attacker:

- approved a big number of tokens to the Uniswap pool

- bought 101 TCR from the pool

- used the loophole to burn the TCR owned by the pool, increasing the TCR price

- used the bought TCR to take away a lot of USDT

Wrong implementation:

function burnFrom(address from, uint256 amount) external {

require(_allowances[msg.sender][from] >= amount, ERROR_ATL);

Correct one:

require(_allowances[from][msg.sender] >= amount, ERROR_ATL);

The actual token implementation allows any account A to burn tokens from any other account B if account A approves that number of tokens to B.

The part of the stolen funds was deposited into Tornado Cash mixer, and the rest holds on the exploiter's address:

https://bloxy.info/txs/transfers_from/0xb19b7f59…e9c299?currency_id=1

Case & protocol details

Classification Token
Protocol Type Exploit/Other
Affected asset / contract TCR
Official Website tecra.space/
Protocol Twitter/X @TecraCoin

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.