TIGER Hack
Incident Overview
TIGER token was rug pulled and the token price dropped by more than 90%. The attacker was related to the initial token holder.
TIGER is a BEP20 token, trading on PancakeSwap. The project can't be confused with other tokens with the same symbol. An EOA address started selling aggressively and dumped the token price on PancakeSwap.
At the token creation transaction, 410,000 $TIGER tokens were minted to an additional address. Afterward, the address transferred tokens to the original attacker's address. The total profit of the attacker reached approximately 784,106 $USD, which was transferred to another address.
Malicious actor address:
https://bscscan.com/address/0x2b7f41d9…471b5a
Initial token holder:
https://bscscan.com/address/0x2c690f9d…49f22f
Tokens transferred to the attacker:
https://bscscan.com/tx/0xdcb323b3…0d84fd
Liquidity pool:
https://bscscan.com/address/0x6f516846…51c700
Incident Report
Protocol Information
Market Context at Time of Hack
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to TIGER, these are the critical security checks that could have prevented this incident (September 2022).
- Verify all logic paths related to Rugpull are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
Learn to Prevent the Next TIGER
The TIGER hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.