Zenon Network Hack
What happened
The attacker's address:
https://bscscan.com/address/0x53d4307d…9c18fd
The transaction behind the attack:
https://bscscan.com/tx/0xc14ae484…5727fc
The Zenon Network hack was made possible by an unprotected burn function within the smart contract. Zenon Network left external access to the burn() function:
https://twitter.com/peckshield/status/1462165620506742784
The attacker deposited tokens in the protocol’s pool for wrapped ZNN (wZNN) tokens and then called the burn function to destroy over 26k wZNN tokens. This decreased the supply of wZNN tokens, increasing their value dramatically. As a result, when the attacker redeemed his wZNN tokens, the pool believed that he was owed a massive number of WBNB tokens, enabling him to drain the pool. Stolen funds were deposited into the Tornado Cash mixer.
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report twitter.com
- report Report halborn.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.