Universe Token Hack

REPORTED LOSS $1.4M
Medium Access Control

What happened

UniverseToken was exploited via access control vulnerability. 1,447,175 $USD worth of assets were stolen and transferred through TornadoCash.

UniverseToken is a DEX on the Binance chain. The project's contract was exploited via access control vulnerability. The $UVT token price dropped by 99% after an incident.

The attacker was able to exploit the controller contract with unverified source code and withdraw roughly 100,000,000 $UVT tokens. Consequently, the tokens were swapped for 5011 $BNB and transferred to the EOA address. All the stolen amount was transferred through TornadoCash.

Attacker addresses:

https://bscscan.com/address/0xf3e3ae9a…f4f760

https://bscscan.com/address/0xbc1ac845…071ef6

Malicious contract:

https://bscscan.com/address/0x99d4311f…f87be9

Malicious transaction:

https://bscscan.com/address/0xbc1ac845…071ef6

Case & protocol details

Classification Exchange (DEX)
Protocol Type Exploit/Access control
Affected asset / contract UVT
Official Website www.uvtoken.com/#/
Protocol Twitter/X @UvTokenOfficial

Evidence & learning

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.