Yoda Coin Hack
Incident Overview
Yoda Coin project rugpulled by the creator who removed all liquidity from UniSwap pool and transferred roughly 114,000 $USD to FixedFloat.
Yoda Coin is an ERC20 token trading on UniSwap. The project experienced a significant drop in price, which turned out to be a rugpull orchestrated by its own creator. The scammer raised 60 $ETH which is worth 114,000 $USD during pre-sale but only added 29 $ETH to LP. Furthermore, multiple $YODA tokens were created with different addresses.
The attacker then removed all available LP funds and migrated them to another contract address while deleting social accounts/groups related to YodaCoin on various platforms.
Scammer Address:
https://etherscan.io/address/0xe9626d14…411272
Initial liquidity transaction:
https://etherscan.io/tx/0xb0dd30a6…7c28cb
Funds transfer transaction:
https://etherscan.io/tx/0x202addc7…d839fd
Incident Report
Protocol Information
Market Context at Time of Hack
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Yoda Coin, these are the critical security checks that could have prevented this incident (May 2023).
- Verify all logic paths related to Rugpull are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
Learn to Prevent the Next Yoda Coin
The Yoda Coin hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.