$22 000 USD

JANUARY 2025

GLOBAL

FORTUNEWHEEL

DESCRIPTION OF EVENTS

FortuneWheel is an "old unknown project contract" on the Binance Smart Chain which was created in June 2023.

 

"The root cause is the swapProfitFees() function which will add BNB to a swap and attack could gain from the K change."

 

"“swapProfitFees” function exchanges tokens using pancakeswap and has no [access] modifier."

 

"this is a classic case of price manipulation. The swapProfitFees() function lacks slippage protection and is easily manipulated by a swap."

 

"Hacker exchanged a huge amount of WBNB to LINK, then called this function, exchanged LINK to WBNB again. He gained almost $21k."

 

Explore This Case Further On Our Wiki

FortuneWheel is a project on the Binance Smart Chain launched in June 2023, identified as an "old unknown project contract." The vulnerability lies in its "swapProfitFees()" function, which facilitates token exchanges using PancakeSwap but lacks an access modifier and slippage protection, making it vulnerable to manipulation. A hacker exploited this weakness by swapping a large amount of WBNB for LINK, then using the function to swap LINK back to WBNB, ultimately making a profit of nearly $21,000 through price manipulation.

Sources And Further Reading

 For questions or enquiries, email info@quadrigainitiative.com.

Get Social

  • email
  • reddit
  • telegram
  • Twitter

© 2019 - 2025 Quadriga Initiative. Your use of this site/service accepts the Terms of Use and Privacy Policy. This site is not associated with Ernst & Young, Miller Thompson, or the Official Committee of Affected Users. Hosted in Canada by HosterBox.