<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=FortuneWheel_swapProfitFees_Access_Control_Issue</id>
	<title>FortuneWheel swapProfitFees Access Control Issue - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=FortuneWheel_swapProfitFees_Access_Control_Issue"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=FortuneWheel_swapProfitFees_Access_Control_Issue&amp;action=history"/>
	<updated>2026-05-02T17:24:19Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=FortuneWheel_swapProfitFees_Access_Control_Issue&amp;diff=6550&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/fortunewheelswapprofitfeesaccesscontrolissue.php}} {{Unattributed Sources}}  BNB Smart Chain ImageFortuneWheel is a project on the Binance Smart Chain launched in June 2023, identified as an &quot;old unknown project contract.&quot; The vulnerability lies in its &quot;swapProfitFees()&quot; function, which facilitates token exchanges using PancakeSwap but lacks an access m...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=FortuneWheel_swapProfitFees_Access_Control_Issue&amp;diff=6550&amp;oldid=prev"/>
		<updated>2025-02-13T22:30:32Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/fortunewheelswapprofitfeesaccesscontrolissue.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Binancesecurity.jpg&quot; title=&quot;File:Binancesecurity.jpg&quot;&gt;thumb|BNB Smart Chain Image&lt;/a&gt;FortuneWheel is a project on the Binance Smart Chain launched in June 2023, identified as an &amp;quot;old unknown project contract.&amp;quot; The vulnerability lies in its &amp;quot;swapProfitFees()&amp;quot; function, which facilitates token exchanges using PancakeSwap but lacks an access m...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/fortunewheelswapprofitfeesaccesscontrolissue.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Binancesecurity.jpg|thumb|BNB Smart Chain Image]]FortuneWheel is a project on the Binance Smart Chain launched in June 2023, identified as an &amp;quot;old unknown project contract.&amp;quot; The vulnerability lies in its &amp;quot;swapProfitFees()&amp;quot; function, which facilitates token exchanges using PancakeSwap but lacks an access modifier and slippage protection, making it vulnerable to manipulation. A hacker exploited this weakness by swapping a large amount of WBNB for LINK, then using the function to swap LINK back to WBNB, ultimately making a profit of nearly $21,000 through price manipulation.&amp;lt;ref name=&amp;quot;fortunewheelexploit-18051&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;tikkalaresearchtwitter-18052&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;0xnicklfranklintwitter-18053&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;nickfranklin-18054&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;fortunewheelcreate-18055&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;tenarmoralerttwitter-18056&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;acaisectwitter-18057&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cnblogs-18058&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About FortuneWheel ==&lt;br /&gt;
FortuneWheel is an &amp;quot;old unknown project contract&amp;quot; on the Binance Smart Chain which was created in June 2023.&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
This sections is included if a case involved deception or information that was unknown at the time. Examples include:&lt;br /&gt;
&lt;br /&gt;
* When the service was actually started (if different than the &amp;quot;official story&amp;quot;).&lt;br /&gt;
* Who actually ran a service and their own personal history.&lt;br /&gt;
* How the service was structured behind the scenes. (For example, there was no &amp;quot;trading bot&amp;quot;.)&lt;br /&gt;
* Details of what audits reported and how vulnerabilities were missed during auditing.&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
&amp;quot;A contract named &amp;quot;FortuneWheel&amp;quot; was exploited due to public swap functionality.&amp;quot;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - FortuneWheel swapProfitFees Access Control Issue&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|June 16th, 2023 8:08:38 PM MDT&lt;br /&gt;
|FortuneWheel Smart Contract Launch&lt;br /&gt;
|The FortuneWheel smart contract is first launched on Binance Smart Chain.&lt;br /&gt;
|-&lt;br /&gt;
|January 10th, 2025 2:40:01 AM MST&lt;br /&gt;
|FortuneWheel Exploit Transaction&lt;br /&gt;
|The FortuneWheel smart contract on Binance Smart Chain is exploited.&lt;br /&gt;
|-&lt;br /&gt;
|January 10th, 2025 2:51:00 AM MST&lt;br /&gt;
|TenArmor Alert Posted&lt;br /&gt;
|TenArmor posts an analysis on their Twitter/X with details of the exploit transaction and cause.&lt;br /&gt;
|-&lt;br /&gt;
|January 10th, 2025 10:18:00 AM MST&lt;br /&gt;
|@ACai_sec Blog Post&lt;br /&gt;
|Twitter user @ACai_sec shares a blog post with an additional analysis and breakdown of events.&lt;br /&gt;
|-&lt;br /&gt;
|January 10th, 2025 10:57:00 AM MST&lt;br /&gt;
|Tikkala Research Twitter/X Post&lt;br /&gt;
|Tikkala research posts about the exploit.&lt;br /&gt;
|-&lt;br /&gt;
|January 10th, 2025 7:29:00 PM MST&lt;br /&gt;
|Nick L. Franklin Twitter/X&lt;br /&gt;
|Nick L. Franklin posts about the exploit to Twitter/X. He has information about the exploit on his site.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
&amp;quot;The root cause is the swapProfitFees() function which will add BNB to a swap and attack could gain from the K change.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;“swapProfitFees” function exchanges tokens using pancakeswap and has no [access] modifier.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;this is a classic case of price manipulation. The swapProfitFees() function lacks slippage protection and is easily manipulated by a swap.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Hacker exchanged a huge amount of WBNB to LINK, then called this function, exchanged LINK to WBNB again. He gained almost $21k.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
The total amount lost has been estimated at $22,000 USD.&lt;br /&gt;
&lt;br /&gt;
How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed?&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done?&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
There do not appear to have been any funds recovered in this case.&lt;br /&gt;
&lt;br /&gt;
What funds were recovered? What funds were reimbursed for those affected users?&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
What parts of this case are still remaining to be concluded?&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;fortunewheelexploit-18051&amp;quot;&amp;gt;[https://bscscan.com/tx/0xd6ba15ecf3df9aaae37450df8f79233267af41535793ee1f69c565b50e28f7da FortuneWheel Smart Contract Exploited] (Accessed Feb 13, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;tikkalaresearchtwitter-18052&amp;quot;&amp;gt;[https://twitter.com/TikkalaResearch/status/1877776767907463222 @TikkalaResearch Twitter] (Accessed Feb 13, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;0xnicklfranklintwitter-18053&amp;quot;&amp;gt;[https://twitter.com/0xNickLFranklin/status/1877905756609257726 @0xNickLFranklin Twitter] (Accessed Feb 13, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;nickfranklin-18054&amp;quot;&amp;gt;[https://nickfranklin.site/2025/01/11/sandwich-attack/ Sandwich attack! – Defi hack analysis] (Accessed Feb 13, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;fortunewheelcreate-18055&amp;quot;&amp;gt;[https://bscscan.com/tx/0x1dcc043b2bdf9be502e71bb720a960e0cecb7e8a9cc7ac73ad79a33f393f8b91 FortuneWheel Smart Contract Creation] (Accessed Feb 13, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;tenarmoralerttwitter-18056&amp;quot;&amp;gt;[https://twitter.com/TenArmorAlert/status/1877654447540592952 @TenArmorAlert Twitter] (Accessed Feb 13, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;acaisectwitter-18057&amp;quot;&amp;gt;[https://twitter.com/ACai_sec/status/1877767094458302551 @ACai_sec Twitter] (Accessed Feb 13, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;cnblogs-18058&amp;quot;&amp;gt;[https://www.cnblogs.com/ACaiGarden/p/18664999 20250110-FortuneWheel 攻击事件：竟然不设滑点，那就体验一下 Force Investment 吧 - ACai_sec - 博客园] (Accessed Feb 13, 2025)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>