Vice.Uno Hack
What happened
The contract deployer added initial liquidity at:
https://www.bscscan.com/tx/0x8cf96acd…664327
The contract deployer used withdrawFromContract() function to transfer tokens from the staking smart contract onto his own address:
https://www.bscscan.com/tx/0x514b2d1a…aaadee
https://www.bscscan.com/tx/0x5287dc65…bfa95b
https://www.bscscan.com/tx/0x51f5e087…ba7193
https://www.bscscan.com/tx/0x61f06484…3b9ed9
https://www.bscscan.com/tx/0xe879e0dd…aab079
https://www.bscscan.com/tx/0x7d1e308f…18a424
https://www.bscscan.com/tx/0x3b8c1983…241fd1
The liquidity was removed by the contract deployer at:
https://www.bscscan.com/tx/0x522b8076…fb91d9
The project's native tokens were sold multiple times as well, the example transaction:
https://www.bscscan.com/tx/0x6fce03df…e93cd1
The stolen BNB tokens were exchanged on Binance BTC tokens at:
https://www.bscscan.com/tx/0x2b181120…de653a
The BTCB tokens were distributed between different external addresses and deposited into the Binance exchange, the example:
https://www.bscscan.com/address/0x734dfb21…f25967#tokentxns
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report vice.uno
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.