EVMInk BNBS Contract Remove Liquidity Reentrancy Attack

From Quadriga Initiative Cryptocurrency Hacks, Scams, and Frauds Repository
Revision as of 16:14, 24 January 2025 by Azoundria (talk | contribs) (Created page with "{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/evminkbnbscontractremoveliquidityreentrancyattack.php}} {{Unattributed Sources}} thumb|EVMInk Logo/HomepageEVMINK has launched a new standard for inscriptions, introducing innovative features for the ecosystem, including native token swaps, on-chain governance, and staking with reward distribution. BNBs were the first to migrate to this new standard, unlocking advanc...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigation Jump to search

Notice: This page is a freshly imported case study from an original repository. While the original content had a similar format, some sections may not have been fully completed. Please help fill in any empty sections or any missing information you can find. If you are new here, please read General Tutorial on Wikis or Anatomy of a Case Study for help getting started.

Notice: This page contains sources which are not attributed to any text. The unattributed sources follow the initial description. Please assist by visiting each source, reviewing the content, and placing that reference next to any text it can be used to support. Feel free to add any information that you come across which isn't present already. Sources which don't contain any relevant information can be removed. Broken links can be replaced with versions from the Internet Archive. See General Tutorial on Wikis, Anatomy of a Case Study, and/or Citing Your Sources Guide for additional information. Thanks for your help!

EVMInk Logo/Homepage

EVMINK has launched a new standard for inscriptions, introducing innovative features for the ecosystem, including native token swaps, on-chain governance, and staking with reward distribution. BNBs were the first to migrate to this new standard, unlocking advanced features such as wallet integration and cheaper gas fees. However, the platform recently experienced a reentrancy exploit, resulting in a loss of approximately $20,300. The vulnerability, found in the "removeLiquidity" function, allowed an attacker to exploit the system by repeatedly withdrawing BNBs without updating the balance. In response, EVMINK temporarily disabled trading to perform security checks and enhance smart contract security. The platform has covered all user losses and is working on strengthening its infrastructure through additional audits and security measures. Trading will resume once internal verifications are complete, ensuring a more resilient and secure platform for users.[1][2][3][4][5][6][7][8][9][10][11][12][13][14][15][16][17][18][19][20]

About EVM Ink

"The communities own indexer Multichain inscription marketplace.Creator launchpad and more."

"We are thrilled to announce the launch of the new standard for inscriptions, marking a transformative milestone for the EVMINK ecosystem.

This update introduces a host of groundbreaking features that elevate how you trade, earn, and interact."

"The New Inscription Token Standard is an enhanced token standard on the EVM blockchain, designed to provide a modular framework of extensions that improve upon the traditional ERC-20 standard."

"- Native Token Swaps: Allows direct token exchanges without relying on decentralized exchanges (DEXs). - On-Chain Governance: Integrates decentralized governance mechanisms directly into token contracts, allowing for efficient decision-making. - Staking and Reward Distribution: Enables native staking functionalities with reward mechanisms."

"We’re proud to announce that BNBs will be the first token to migrate to our revolutionary new inscription token standard. As the largest inscription token on @BNBCHAIN by Volume and market cap, BNBs continues to set the benchmark for excellence and innovation.

This migration marks a new chapter for all inscriptions as BNBs will take the lead, unlocking advanced features like wallet integration, swapping, liquidity pools, and cheaper gas fees under the new standard. The future of inscriptions is here, and it starts with BNBs leading the charge!"

The Reality

"In removeLiquidity() function, token transfer should happen before ETH transfer because token balance is used to calculate amountNative and amountToken to remove."

What Happened

"A suspicious reentrancy attack involving bnbs (bnbs) occurred on the BSC chain, resulting in a loss of approximately $20,300."

Key Event Timeline - EVMInk BNBS Contract Remove Liquidity Reentrancy Attack
Date Event Description
December 9th, 2024 3:14:00 AM MST New Token Inscription Standard EVMInk announces a new token inscription standard on their website.
December 10th, 2024 4:09:00 AM MST Launch Announces As Success EVMInk highlightes the success of their new launch, with notable statistics including $160K+ in daily trading volume, 550+ users migrated to new Token Standard, $50K+ locked in liquidity, and 1,500 transactions.
December 11th, 2024 12:58:00 AM MST Thrilled With Audit Announcement "We’re thrilled to announce that BNBs’s smart contract has been audited and verified, solidifying our commitment to security with zero compromises."
December 11th, 2024 5:45:21 PM MST Binance Smart Chain Transaction The malicious transaction which is reported by SlowMist.
December 11th, 2024 7:11:00 PM MST TenArmor Transaction Analysis The TenArmor team posts an initial analysis of the exploit and
December 11th, 2024 7:28:00 PM MST Huge Gas Fees Analysis Underway "Our team is currently fixing some bugs on the huge gas fee involved, and modify the issue happens on UI side. Please DO NOT do any transactions / activity until further notice. Everyone's assets are secured and safe."
December 11th, 2024 7:33:00 PM MST Hermione7812 Reply To TenArmor Analysis Hermione7812 responds to the initial TenArmor tweet with additional information about the vulnerability. "In removeLiquidity() function, token transfer should happen before ETH transfer because token balance is used to calculate amountNative and amountToken to remove."
December 12th, 2024 12:19:00 AM MST Issue Unfortunately Announcement The EVMInk team posts an announcement that there has been an issue. They are working with their audit partner Quill Audits towards a resolution.
December 12th, 2024 12:41:00 AM MST Quill Audits Announcing Postmortem Quill Audits announces that they are conducting a post-mortem and will be sharing their results with the team shortly.
December 12th, 2024 7:29:00 AM MST Audit911 Analysis Posted Audit911 posts an analysis of the exploit on Twitter/X. Their AI detection program reportedly found the vulnerability.
December 12th, 2024 12:11:00 PM MST Tikkala Research Analysis Tikkala Research posts an announcement of the vulnerability, reporting this as a "classical re-entry bug". They edit moments later to add the transaction link.
December 12th, 2024 12:55:00 PM MST Tikkala Research Analysis Tikkala Research posts a more detailed analysis,
December 17th, 2024 2:46:00 AM MST Nick L Franklin Analysis Nick L Franklin posts a technical analysis of the exploit with additional details, which references a post on his website.
December 19th, 2024 3:38:00 AM MST Downtime For Security Check The platform announces downtime in order to perform a security check.
January 11th, 2025 4:09:00 AM MST Working Through Towards Relaunch The platform posts an update that they are siligently working through security checks and plan to relaunch shortly.

Technical Details

"A classical re-entry bug hit one of the @evmink new BNBS contract which leads ~20k lost. Attacker has been labeled as "FEGtoken Exploiter"."

"root cause is the balance update after the re-entry which impacts the K value. Later on a small amount of bnbs token could swap out almost all BNB in the victim account."

"bnbs token exploit. Root cause of bnbs exploit is reentrance. "removeLiquidity" function has no reentrance check, and bnbs balance is updated after eth sent, this can be used for reentrance attack. As you can see, "removeLiquidity" function is called in fallback function, and in each "removeLiquidity" function, he gets more and more bnbs tokens, as bnbs balance is not updated. After that, he exchanged all bnbs tokens to WBNB, total loss is about $20k."

Total Amount Lost

The total amount lost has been estimated at $20,000 USD.

How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?

Immediate Reactions

"Our team is currently fixing some bugs on the huge gas fee involved, and modify the issue happens on UI side.

Please DO NOT do any transactions / activity until further notice. Everyone's assets are secured and safe."

"there’s been an issue unfortunately, and our team is actively working to resolve it. alongside our audit partners, @quillaudits_ai. user funds remain safe and secured. we’ll provide more updates shortly—thank you for your patience as we ensure everything is back on track."

Audit911 reports that their "team detected today that the bnbs project was hacked and the funds lost were ~20ku. Our AI detection system can already identify this vulnerability"

"A suspicious reentrancy attack involving bnbs (bnbs) occurred on the BSC chain, resulting in a loss of approximately $20,300."

Ultimate Outcome

What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done?

Total Amount Recovered

Protocol has promised to cover all user assets.

There do not appear to have been any funds recovered in this case.

Ongoing Developments

"We have scheduled temporarily disable EVMINK platform to facilitate the final phase of internal security checks, ensuring a smooth and comprehensive process. This follows the completion of a rigorous security audit and reflects our commitment to maintaining the highest levels of safety and reliability for our users.

Please note: - All user funds remain secure, the liquidity pools are fully operational. - Once the platform is reactivated, tokens will be reallocated and issued promptly to all eligible users.

In the background, we are also preparing additional features aligned with the new token standard and working closely with the community to refine and enhance the ecosystem.

We appreciate your patience and support as we prioritize the security and performance of our platform. Updates will be provided through our official channels.

Thank you for your trust, All funds are SAFE."

"Trading is temporarily halted, We are investigating the issues with liquidity pool"

"Over the past few weeks, we have been diligently reinforcing the security of our platform after identifying a vulnerability in our smart contract, which led to an on-chain attack resulting in a $20.3K loss. While this was an unexpected setback, it has provided us with an opportunity to strengthen our security framework and ensure a more resilient platform moving forward."

"User funds remain fully protected – EVMINK has covered the entire loss from our reserves, ensuring that no user assets are affected. Reinforced smart contract security – Additional audits and advanced security measures have been implemented to prevent similar exploits. Comprehensive system improvements – Beyond just fixing the issue, we have enhanced the entire infrastructure to make the platform stronger and more efficient."

"We are approaching the final stage of internal security verification. Over the next few days, we will be announcing a strategic launch date for the platform, ensuring that we go live with maximum confidence and stability.

This is more than just a relaunch—it’s a major step forward. The lessons learned have allowed us to build an even stronger foundation, and we are excited for what’s ahead. Thank you for your patience, trust, and support as we prepare for a new and improved EVMINK."

Individual Prevention Policies

No specific policies for individual prevention have yet been identified in this case.

For the full list of how to protect your funds as an individual, check our Prevention Policies for Individuals guide.

Platform Prevention Policies

Policies for platforms to take to prevent this situation have not yet been selected in this case.

For the full list of how to protect your funds as a financial service, check our Prevention Policies for Platforms guide.

Regulatory Prevention Policies

No specific regulatory policies have yet been identified in this case.

For the full list of regulatory policies that can prevent loss, check our Prevention Policies for Regulators guide.

References

  1. BNB Smart Chain Transaction Hash (Txhash) Details | BscScan (Accessed Jan 24, 2025)
  2. BlockThreat - Week 50, 2024 (Accessed Jan 24, 2025)
  3. @TikkalaResearch Twitter (Accessed Jan 24, 2025)
  4. @TikkalaResearch Twitter (Accessed Jan 24, 2025)
  5. Inscriptions (Accessed Jan 24, 2025)
  6. @evmink Twitter (Accessed Jan 24, 2025)
  7. @evmink Twitter (Accessed Jan 24, 2025)
  8. @evmink Twitter (Accessed Jan 24, 2025)
  9. @evmink Twitter (Accessed Jan 24, 2025)
  10. @evmink Twitter (Accessed Jan 24, 2025)
  11. @quillaudits_ai Twitter (Accessed Jan 24, 2025)
  12. @LucidSamuel_ Twitter (Accessed Jan 24, 2025)
  13. QuillAudit_Reports/EVM.INK Smart Contract Audit Report - QuillAudits.pdf at master · Quillhash/QuillAudit_Reports · GitHub (Accessed Jan 24, 2025)
  14. @evmink Twitter (Accessed Jan 24, 2025)
  15. @evmink Twitter (Accessed Jan 24, 2025)
  16. @0xNickLFranklin Twitter (Accessed Jan 24, 2025)
  17. bnbs token exploit. – Defi hack analysis (Accessed Jan 24, 2025)
  18. @TenArmorAlert Twitter (Accessed Jan 24, 2025)
  19. @Hermione7812 Twitter (Accessed Jan 24, 2025)
  20. @audit_911 Twitter (Accessed Jan 24, 2025)