YEED Hack
What happened
YEED Token was dumped due to the exploit with a profit of about 1M+ $USD.
The hacker has performed transfers to three trading pairs, namely ZEED, HOR, and USDT via YEED. This process has been repeated multiple times. The ZEED tokens are directly added or subtracted from the balance of the trading pair, which creates a vulnerability that the hacker exploits.
This vulnerability allows the hacker to increase the balance and receive excess rewards from the pair. The attack leverages the ZEED contract's direct calculation of the balance using the rewardFee but not using the separate calculation of zedreward, horward, usdtreward. This vulnerability is used to generate profits for the hacker.
The total amount of funds stolen is estimated at $1,043,070. The hacker has not yet transferred out the funds, as the contract has already self-destructed.
Exploit TXs:
https://bscscan.com/tx/0x05074762…3fa83a
Exploiter address:
https://bscscan.com/address/0xec14207d…6e0fb0
Attacker contract:
https://bscscan.com/address/0x05e55d05…103374
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report twitter.com
- report Post-mortem mirror.xyz
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.