WOLF Protocol Hack
What happened
The deployer of the WOLF Protocol exploited users by trapping liquidity providers through locking funds and minting $WFLP token to an EOA that was not blacklisted. This exploit netted the deployer approx. $30k in ill-gotten funds.
The Wolf protocol promised to be a DeFi revolution offering staking and yield solutions on three different blockchains. The website boasted a fake team and a fake roadmap. The smart contract contained malicious rights that could only be invoked by the token deployer and enabled a centralized token balance modification. In simple terms, the token deployer could change the balance of any holder.
The contract deployer added initial liquidity at:
https://etherscan.io/tx/0x28d4d2d4…800bb1
This made the token tradable. Within 11 days, the community noticed that the $WLFP could not be sold or withdrawn. The root of this can be found in this transaction, where the contract deployer locked liquidity:
https://etherscan.io/tx/0x4b4c0578…872912
After users were trapped the contract deployer proceeded to invoke the approveAndCall() function, which included an external wallet and addedValue amount as the input data:
https://etherscan.io/tx/0xa0dcdb89…964401
After the external wallet received the enhancement in its token balance, the external wallet dumped $WLFP for $ETH34t:
https://etherscan.io/tx/0x54e39afc…b88593
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report twitter.com
- analysis Web Archive archive.ph
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.