<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Standing_on_Bizness_%28BIZNESS%29_SplitLock_Reentrancy_Attack</id>
	<title>Standing on Bizness (BIZNESS) SplitLock Reentrancy Attack - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Standing_on_Bizness_%28BIZNESS%29_SplitLock_Reentrancy_Attack"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Standing_on_Bizness_(BIZNESS)_SplitLock_Reentrancy_Attack&amp;action=history"/>
	<updated>2026-06-10T12:11:28Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Standing_on_Bizness_(BIZNESS)_SplitLock_Reentrancy_Attack&amp;diff=6503&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study 2 With About|source=https://www.quadrigainitiative.com/casestudy/standingonbiznessbiznesssplitlockreentrancyattack.php}} {{Unattributed Sources}}  Standing on Bizness Homepage&quot;Standing on Bizness&quot; launched the $bizness token on the Base blockchain on November 20th, 2024, with a focus on building a community through its Telegram and Twitter channels. The token, introduced as the first tokenized belief coin from to...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Standing_on_Bizness_(BIZNESS)_SplitLock_Reentrancy_Attack&amp;diff=6503&amp;oldid=prev"/>
		<updated>2025-01-31T18:29:54Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study 2 With About|source=https://www.quadrigainitiative.com/casestudy/standingonbiznessbiznesssplitlockreentrancyattack.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Standingonbizness.jpg&quot; title=&quot;File:Standingonbizness.jpg&quot;&gt;thumb|Standing on Bizness Homepage&lt;/a&gt;&amp;quot;Standing on Bizness&amp;quot; launched the $bizness token on the Base blockchain on November 20th, 2024, with a focus on building a community through its Telegram and Twitter channels. The token, introduced as the first tokenized belief coin from to...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study 2 With About|source=https://www.quadrigainitiative.com/casestudy/standingonbiznessbiznesssplitlockreentrancyattack.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Standingonbizness.jpg|thumb|Standing on Bizness Homepage]]&amp;quot;Standing on Bizness&amp;quot; launched the $bizness token on the Base blockchain on November 20th, 2024, with a focus on building a community through its Telegram and Twitter channels. The token, introduced as the first tokenized belief coin from toshimart.xyz, gained attention through updates about its availability on Uniswap, along with the contract address and community-building messages. However, the project's smart contract contained a vulnerability in the &amp;quot;splitLock&amp;quot; function, which lacked a reentrancy check, allowing an attacker to exploit the system and withdraw more tokens than intended. This flaw led to a $16,000 loss, but the incident was not mentioned on their Twitter account, and promotions continued post-hack. Despite coverage of the hack by Nick L. Franklin and inclusion in the SlowMist list, the team has not publicly acknowledged the exploit.&amp;lt;ref name=&amp;quot;exploittransaction-17760&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;0xnicklfranklintwitter-17761&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;nickfranklin-17762&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;mizar-17763&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;biznesscontract-17764&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;biznesscreation-17765&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;biznesshomepage-17766&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;trybeforediepost-17767&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;thiscatpost-17768&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;dextools-17769&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;blocksecapp-17770&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;biznessexploiter-17771&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;tenarmoralerttwitter-17772&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About Standing On Bizness ==&lt;br /&gt;
&amp;quot;Standing on Bizness&amp;quot; is a $bizness token launched on the Base blockchain on November 20th. To join the community, you can connect through their Telegram and X/Twitter channels. The contract address for $bizness is 0xF3a605573B93Fd22496f471A88AE45F35C1df5A7.&lt;br /&gt;
&lt;br /&gt;
The Standing On Bizness (@SOB_base) Twitter account is focused on promoting its $bizness token, which launched as the first tokenized belief coin from the toshimart.xyz platform. Their Twitter activity includes sharing updates about the token's availability on Uniswap, contract address, and a link to their Telegram group. They emphasize a &amp;quot;mean what you say, say what you mean&amp;quot; motto and encourage users to be part of the community, branding themselves as &amp;quot;standing ten toes down&amp;quot; on their business.&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
The smart contract lacked a reentrancy check in the &amp;quot;splitLock&amp;quot; function, allowing attackers to exploit it by withdrawing more tokens than intended before the locked amount was updated.&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
BIZNESS on base was hacked due to a reentrancy vulnerability in the &amp;quot;splitLock&amp;quot; function, resulting in a $16,000 loss.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - Standing on Bizness (BIZNESS) SplitLock Reentrancy Attack&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|November 20th, 2024 8:44:41 AM MST&lt;br /&gt;
|Token Launch On Base&lt;br /&gt;
|The Standing On Bizness token is first launched on the Base blockchain.&lt;br /&gt;
|-&lt;br /&gt;
|December 26th, 2024 6:28:00 PM MST&lt;br /&gt;
|This Cat Means Bizness&lt;br /&gt;
|A promotion on Twitter of a cat opening blinds.&lt;br /&gt;
|-&lt;br /&gt;
|December 27th, 2024 7:42:55 PM MST&lt;br /&gt;
|Base Exploit Transaction&lt;br /&gt;
|The token is exploited via the re-entrancy attack.&lt;br /&gt;
|-&lt;br /&gt;
|December 27th, 2024 9:08:00 PM MST&lt;br /&gt;
|TenArmor Tweet Posted&lt;br /&gt;
|TenArmor shares a tweet on their Twitter account about the exploit.&lt;br /&gt;
|-&lt;br /&gt;
|December 28th, 2024 2:53:00 PM MST&lt;br /&gt;
|The Price Of Winning Post&lt;br /&gt;
|A new promotion, to &amp;quot;[b]e an alpha Stand on $BIZNESS&amp;quot; with a video comparing &amp;quot;the price of winning&amp;quot; and &amp;quot;the bill from regret&amp;quot;.&lt;br /&gt;
|-&lt;br /&gt;
|January 7th, 2025 6:30:00 PM MST&lt;br /&gt;
|Nick L Franklin Analysis&lt;br /&gt;
|Nick L Franklin publishes an analysis of the exploit reentrancy attack.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
BIZNESS on base was hacked due to a reentrancy vulnerability in the &amp;quot;splitLock&amp;quot; function of its Locker contract. The function calls the &amp;quot;_feeHandler()&amp;quot; to send fees to the treasury and remaining funds to the user, but lacks a reentrancy check. This allows an attacker to exploit the vulnerability by triggering the &amp;quot;withdrawLock()&amp;quot; function before the locked amount is updated, enabling them to withdraw more tokens than intended. The total loss from the attack was approximately $16,000.&lt;br /&gt;
&lt;br /&gt;
&amp;quot;The splitLock function in the Locker contract reduces the lock amount and creates a new lock after calling the _feeHandler function, which sends surplus ETH to msg.sender. &lt;br /&gt;
&lt;br /&gt;
This creates an opportunity for reentrancy, allowing the attacker to call the withdrawLock function and withdraw tokens while simultaneously creating a new lock, due to the lock amount not being updated.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
The hack resulted in a loss of approximately $16,000 worth of tokens due to the reentrancy vulnerability in the smart contract.&lt;br /&gt;
&lt;br /&gt;
The total amount lost has been estimated at $16,000 USD.&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
The hack was not mentioned on the Twitter/X account. Promotions continued the next day, including a post about being &amp;quot;an alpha Stand on $BIZNESS&amp;quot; with a video comparing &amp;quot;the price of winning&amp;quot; and &amp;quot;the bill from regret&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
Some time later, the incident was covered by Nick L Franklin and included in the SlowMist list.&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
The team does not appear to have acknowledged any exploit.&lt;br /&gt;
&lt;br /&gt;
There do not appear to have been any funds recovered in this case.&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
What parts of this case are still remaining to be concluded?&lt;br /&gt;
== General Prevention Policies ==&lt;br /&gt;
Developers need to implement proper reentrancy protections to prevent similar exploits in the future.&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;exploittransaction-17760&amp;quot;&amp;gt;[https://basescan.org/tx/0x984cb29cdb4e92e5899e9c94768f8a34047d0e1074f9c4109364e3682e488873 The Exploit Transaction] (Accessed Jan 31, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;0xnicklfranklintwitter-17761&amp;quot;&amp;gt;[https://twitter.com/0xNickLFranklin/status/1876803706810683849 @0xNickLFranklin Twitter] (Accessed Jan 31, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;nickfranklin-17762&amp;quot;&amp;gt;[https://nickfranklin.site/2025/01/08/bizness-hacked/ BIZNESS hacked. – Defi hack analysis] (Accessed Jan 31, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;mizar-17763&amp;quot;&amp;gt;[https://mizar.com/token-sniffer/token/standing-on-bizness Standing on Bizness price today, BIZNESS to USD live price, marketcap and chart | Mizar] (Accessed Jan 31, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;biznesscontract-17764&amp;quot;&amp;gt;[https://basescan.org/address/0xf3a605573b93fd22496f471a88ae45f35c1df5a7 The Bizness Token Contract On Base] (Accessed Jan 31, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;biznesscreation-17765&amp;quot;&amp;gt;[https://basescan.org/tx/0x9815bb4a4246d0f0651cfdfe7ef611021a4ec8ca65957d9906a6e9581749f6ea Transaction Creating Bizness Token] (Accessed Jan 31, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;biznesshomepage-17766&amp;quot;&amp;gt;[https://standingonbiz.meme/ Standing On Bizness Homepage] (Accessed Jan 31, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;trybeforediepost-17767&amp;quot;&amp;gt;[https://twitter.com/SOB_base/status/1873125094157062629 Bizness - &amp;quot;Try before you die or always wonder... What if?? Be an alpha Stand on $BIZNESS&amp;quot; - Twitter] (Accessed Jan 31, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;thiscatpost-17768&amp;quot;&amp;gt;[https://twitter.com/SOB_base/status/1872454405448221124 Bizness - &amp;quot;This cat is Standing on $BIZNESS&amp;quot; - Twitter] (Accessed Jan 31, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;dextools-17769&amp;quot;&amp;gt;[https://www.dextools.io/app/en/base/pair-explorer/0x599245fafc9a55e3d2f02176a65d9cd302023c61 https://www.dextools.io/app/en/base/pair-explorer/0x599245fafc9a55e3d2f02176a65d9cd302023c61] (Accessed Jan 31, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;blocksecapp-17770&amp;quot;&amp;gt;[https://app.blocksec.com/explorer/tx/base/0x984cb29cdb4e92e5899e9c94768f8a34047d0e1074f9c4109364e3682e488873 0x984cb29cdb4e92e589 | Phalcon Explorer] (Accessed Jan 31, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;biznessexploiter-17771&amp;quot;&amp;gt;[https://basescan.org/address/0x3cc1edd8a25c912fcb51d7e61893e737c48cd98d Bizness Exploiter Address] (Accessed Jan 31, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;tenarmoralerttwitter-17772&amp;quot;&amp;gt;[https://twitter.com/TenArmorAlert/status/1872857132363645205 @TenArmorAlert Twitter] (Accessed Jan 31, 2025)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>