Unidark Hack
What happened
The project team announced an airdrop as well as a token sale. They used Telegram to spread phony Vitalik Buterin statements about their token in order to boost the trust. The contract deployer with malicious rights called a function named clearETH(), which allowed him to transfer ETH to his own address. As a result, 85.1 ETH was withdrawn from the token contract. Users contacted Binance's technical support. In the end, the address of the deployer was frozen on the exchange.
The transaction where the mentioned function was invoked:
https://etherscan.io/tx/0xfa04a396…bda75a
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report t.me
- analysis Web Archive web.archive.org
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.