Vice.Uno Hack
Incident Overview
The contract deployer added initial liquidity at:
https://www.bscscan.com/tx/0x8cf96acd…664327
The contract deployer used withdrawFromContract() function to transfer tokens from the staking smart contract onto his own address:
https://www.bscscan.com/tx/0x514b2d1a…aaadee
https://www.bscscan.com/tx/0x5287dc65…bfa95b
https://www.bscscan.com/tx/0x51f5e087…ba7193
https://www.bscscan.com/tx/0x61f06484…3b9ed9
https://www.bscscan.com/tx/0xe879e0dd…aab079
https://www.bscscan.com/tx/0x7d1e308f…18a424
https://www.bscscan.com/tx/0x3b8c1983…241fd1
The liquidity was removed by the contract deployer at:
https://www.bscscan.com/tx/0x522b8076…fb91d9
The project's native tokens were sold multiple times as well, the example transaction:
https://www.bscscan.com/tx/0x6fce03df…e93cd1
The stolen BNB tokens were exchanged on Binance BTC tokens at:
https://www.bscscan.com/tx/0x2b181120…de653a
The BTCB tokens were distributed between different external addresses and deposited into the Binance exchange, the example:
https://www.bscscan.com/address/0x734dfb21…f25967#tokentxns
Incident Report
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Vice.Uno, these are the critical security checks that could have prevented this incident (October 2020).
- Verify all logic paths related to Rugpull are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
-
01
Source 1 https://vice.uno/
Learn to Prevent the Next Vice.Uno
The Vice.Uno hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.