Bankroll is reportedly attacked and CoW laundering| Cointelegraph

DeFi exploits: Bankroll is reportedly drained of $230,000

According to a Sept. 23 X post from blockchain security platform TenArmor, a hacker attacked the decentralized finance protocol Bankroll Network on Sept. 22, draining $230,000 from it.

TenArmor posted an image of the attack transactions. It shows numerous transfers of BNB from a BankrollNetworkStack contract to itself, each worth $9,679,645.51.

Two other transfers are for $9,435,877.94, one of which comes from a PancakeSwap exchange pool and is sent to an account ending in “47D7,” while the other comes from the “47D7” account and is sent to the BankrollNetworkStack contract. 

The difference between the self-transfers and the transfer to the account is $243,767.57, which is approximately equal to the $235,000 stated as the loss amount.

Given this information, the attacker may have exploited a vulnerability that allowed them to withdraw more than they deposited and used flash loans to make the initial deposit.

Bankroll Network attack transactions. (TenArmorAlert)

Blockchain data confirms that the transfers happened at 4:50 pm UTC on Sept. 22. Cointelegraph contacted the Bankroll Network team via Telegram but did not receive a response by the time of publication.

DeFi exploits are a frequent cause of losses to Web3 users. Users should carefully research a protocol’s security before using it. Protocols that are audited by reputable smart contract security firms are more likely to be secure, although this cannot 100% guarantee that vulnerabilities don’t exist.

Bankroll Network has not confirmed that this transaction is an exploit, and security researchers may report new information about it as their investigations continue. This is a developing story and may be updated over time.

Phish of the week: Phisher moved $250,000 through CoW

On Aug. 28, a phishing attacker who previously drained a crypto whale’s wallet of $55.4…

..

Read More

Recommended For You

Leave a Reply

Your email address will not be published. Required fields are marked *