logo

GYM Network Exploit Analysis

ID: 2fe5054c-1b51-50d0-a0a2-bcd9751e9e9d

STIX ID: report--2fe5054c-1b51-50d0-a0a2-bcd9751e9e9d

Feed Name: CertiK Blog

Threat Score
72/100

Date Published: 2022-06-08

Date Updated: 2026-06-11

...
...

On June 8, 2022 a vulnerability in GYM Network's recently deployed contract function (depositFromOtherContract/_autoDeposit) allowed an attacker to create deposit records without transferring tokens and repeatedly withdraw value, resulting in a theft of approximately 2,475.91 WBNB (~$716K). The team patched the function by adding an onlyBank modifier and plans treasury actions to stabilize token price; the attacker laundered proceeds via Tornado Cash.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.