Time Hack

TOTAL LOST $200K
Low Other ethereum

What happened

Time token, an ERC20 token on Ethereum, suffered a price manipulation exploit on Dec 6, 2023, resulting in a loss of 94 ETH or $200,000 USD.

On December 6, 2023, Time token was exploited due to a smart contract vulnerability that allowed price manipulation via a public burn issue and vulnerable ERC2771 standard. The attacker exploited the vulnerable Forwarder contract and was able to drain funds from the DEX by burning TIME tokens to inflate the token price and take away rewards. The exploit resulted in a loss of 94 ETH, equivalent to approximately $200,000 USD.

Thirdweb, the deployer of the TimeToken contract, had issued a community alert regarding the security vulnerability on December 5th, 2023, following an internal disclosure on November 20, 2023. Users who deployed impacted pre-built smart contracts before November 22, 2023, at 7 PM PST need to take specific mitigation steps to address the vulnerability identified by Thirdweb. The stolen funds are currently at the malicious contract.

Attacker Address:

https://etherscan.io/address/0xfde0d157…81455a

Malicious Transaction:

https://etherscan.io/tx/0xecdd111a…d2f6b6

Malicious Contract Address:

https://etherscan.io/address/0x6980a47b…bdbdd0

Case & protocol details

Classification Token / Input Validation
Protocol Type Exploit/Other
Affected asset / contract TIME
Smart Contract Language Solidity
Official Website time.meme/
Protocol Twitter/X @timecoineth

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.