TokenHolder Hack
What happened
On October 8, 2025, an attacker drained 20 WBNB from the TokenHolder lending vault of a small leveraged-trading protocol on BNB Chain. The vault's privilegedLoan() function was correctly restricted to the protocol's router, BorrowerOperationsV6. The router's sell() function, however, was open to anyone, had its whitelist checks commented out, and made an arbitrary call to a router address and calldata supplied by the caller. The attacker used sell() to make the router call privilegedLoan() on the vault, supplied a fake loan contract so that repayment did nothing, and received the borrowed WBNB as trading profit. An 8% fee (1.6 WBNB) was taken from that profit, half of which went to the protocol fee address and half back to the attacker as integrator fee, so the attacker kept about 19.2 WBNB and the protocol fee address received 0.8 WBNB.
Exploit transaction: 0xc291d70f281dbb6976820fbc4dbb3cfcf56be7bf360f2e823f339af4161f64c6. Attacker: 0x3fee6d8aaea76d06cf1ebeaf6b186af215f14088. Attack contract: 0xe82Fc275B0e3573115eaDCa465f85c4F96A6c631.
How it happened
- The attacker's contract called
BorrowerOperationsV6.sell(), passing its own address as thetokenHolder, integrator fee address and whitelisted DEX, and the real TokenHolder vault asinchRouter. sell()read the loan from the attacker-suppliedtokenHolder, so the attacker's contract returned fabricated loan data.sell()then executedinchRouter.call(sellingCode)withsellingCodeset toprivilegedLoan(WBNB, 20 ether). The call came from BorrowerOperationsV6, which holdsBORROWER_ROUTER_ROLE, so the vault sent 20 WBNB to the router.sell()calledrepayLoan()on the attacker's faketokenHolder, which did nothing, and then paid out the 20 WBNB as the trader's profit: an 8% fee (1.6 WBNB) was split into 0.8 WBNB for the protocol fee address and 0.8 WBNB for the attacker-set integrator fee address, and the remaining 18.4 WBNB went to the attacker, so the attack contract received 19.2 WBNB in total.
Protocol details
Evidence
- transaction BscScan transaction 0xc291d70f...64c6 (Wayback copy, 2026-02-18) web.archive.org
- analysis DeFiLlama defillama.com
- analysis TokenHolder / BorrowerOperationsV6 Exploit: Privileged-Role Confused-Deputy Drain via sell()'s Arbitrary Call (Crypto Training) crypto.training
- analysis DeFiHackLabs TokenHolder_exp.sol raw.githubusercontent.com
- analysis Defimon alert 2027: TokenHolder lost $21,412 t.me
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.