TokenHolder Hack

Reported loss $26K
BNB Chain
Improper Access Control

What happened

On October 8, 2025, an attacker drained 20 WBNB from the TokenHolder lending vault of a small leveraged-trading protocol on BNB Chain. The vault's privilegedLoan() function was correctly restricted to the protocol's router, BorrowerOperationsV6. The router's sell() function, however, was open to anyone, had its whitelist checks commented out, and made an arbitrary call to a router address and calldata supplied by the caller. The attacker used sell() to make the router call privilegedLoan() on the vault, supplied a fake loan contract so that repayment did nothing, and received the borrowed WBNB as trading profit. An 8% fee (1.6 WBNB) was taken from that profit, half of which went to the protocol fee address and half back to the attacker as integrator fee, so the attacker kept about 19.2 WBNB and the protocol fee address received 0.8 WBNB.

Exploit transaction: 0xc291d70f281dbb6976820fbc4dbb3cfcf56be7bf360f2e823f339af4161f64c6. Attacker: 0x3fee6d8aaea76d06cf1ebeaf6b186af215f14088. Attack contract: 0xe82Fc275B0e3573115eaDCa465f85c4F96A6c631.

How it happened

  1. The attacker's contract called BorrowerOperationsV6.sell(), passing its own address as the tokenHolder, integrator fee address and whitelisted DEX, and the real TokenHolder vault as inchRouter.
  2. sell() read the loan from the attacker-supplied tokenHolder, so the attacker's contract returned fabricated loan data.
  3. sell() then executed inchRouter.call(sellingCode) with sellingCode set to privilegedLoan(WBNB, 20 ether). The call came from BorrowerOperationsV6, which holds BORROWER_ROUTER_ROLE, so the vault sent 20 WBNB to the router.
  4. sell() called repayLoan() on the attacker's fake tokenHolder, which did nothing, and then paid out the 20 WBNB as the trader's profit: an 8% fee (1.6 WBNB) was split into 0.8 WBNB for the protocol fee address and 0.8 WBNB for the attacker-set integrator fee address, and the remaining 18.4 WBNB went to the attacker, so the attack contract received 19.2 WBNB in total.

Protocol details

Classification Access Control
Protocol Type Token
Implementation language Solidity

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.