Treasure Swap Hack

TOTAL LOST $1.1M
Medium Other

What happened

The Treasure Swap project has been exploited by hackers. Using the vulnerability, the hacker needed only 1 wei to exchange all the $WETH tokens in the transaction pool.

Treasure Swap is a donation protocol driven by the community to build a sustainable DAO.

The hacker noticed a vulnerability in the Treasure Swap contract, where in the swap function the check for the k-value of the constant formula k = a * b, which determines the price of the token (A) in the token (B), was skipped. The hacker noticed this vulnerability, deployed his malicious contracts on the network with which he began to steal the $WETH reserves from the protocol.

Example transactions of the exploit:

  1. Tx
  2. Tx
  3. Tx

All stolen $BNB are still held on the hacker's wallet.

Hacker address: https://bscscan.com/address/0x0FaCB17e…b5931D

Vulnerable contract addresses:

  1. Address
  2. Address

Malicious contract addresses:

  1. Address
  2. Address
  3. Address

Case & protocol details

Classification Exchange (DEX)
Protocol Type Exploit/Other
Official Website treasureswap.net/
Protocol Twitter/X @treasure__swap

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.