GYM Network Exploit Analysis
ID: 2fe5054c-1b51-50d0-a0a2-bcd9751e9e9d
STIX ID: report--2fe5054c-1b51-50d0-a0a2-bcd9751e9e9d
Feed Name: CertiK Blog
Threat Score
On June 8, 2022 a vulnerability in GYM Network's recently deployed contract function (depositFromOtherContract/_autoDeposit) allowed an attacker to create deposit records without transferring tokens and repeatedly withdraw value, resulting in a theft of approximately 2,475.91 WBNB (~$716K). The team patched the function by adding an onlyBank modifier and plans treasury actions to stabilize token price; the attacker laundered proceeds via Tornado Cash.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
