Cryptocurrency [loss] $2M+

Tweet by PeckShield

2022-04-11 [vendor] Creat Future [chain] bsc
Primary Source ↗
Financial Loss $1.9M (1,900,000 USD)
Blockchain(s) Bsc

Incident Details

An attacker stole about $1.9 million after exploiting a bug in the smart contract for the Creat Future token. The contract’s transfer function was defined as public, with no validation on the caller, allowing anyone to transfer tokens from any wallet. An attacker quickly exploited this flaw to drain millions of $CF tokens from various wallets, then exchange and tumble them to cover their tracks. The attacker made off with about $1.9 million, and the value of $CF crashed.$CF was an asset belonging to Creat Future, an early-stage defi project. Some have speculated that the hack was an inside job, and the vulnerable function was added intentionally.

Total loss estimated at $1,900,000.

Technical Details

Initial Attack Vector
Smart contract exploit / hack
Vendor / Product
Creat Future

Timeline

  1. 2022-04-11 Breach occurred
  2. 2022-04-11 Publicly disclosed