Revoke.cash logo

Bancor Hack

Check if your address is affected.

18 Jun 2020
$135k stolen
Ethereum Logo

Bancor is a decentralized exchange on Ethereum. On 16 June 2020 it deployed a new version of its main trading contract, and users who traded through it approved it to spend their tokens. Two days later, on 18 June 2020, the team learned that the new contract had a serious bug: a transfer function that was only meant to be used by the contract itself had been left open to everyone. This meant that anyone could move tokens out of any wallet that had approved the vulnerable Bancor contracts.

Instead of waiting for attackers to find the bug, Bancor used it first, moving at-risk tokens out of users' wallets and into a safe wallet. This rescued over $400k of user funds. But two automated front-running bots spotted the rescue, copied it and got ahead of the team, taking about $135k of user funds for themselves. At the time, Bancor said it was in contact with the bot owners and working with them to return the money in exchange for a bug bounty. Bancor then deployed a fixed contract, and trading went back to normal.

The new contract replaced the vulnerable ones for trading, but it did not cancel the approvals that users had already given to the old contracts. At the time, Bancor told affected users to revoke those approvals. If you traded on Bancor around June 2020, check your wallet and revoke any approvals that remain for these old Bancor contracts. Revoking protects the tokens that are still in your wallet, but it does not bring back funds that were already taken.

Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.

Next time, revoke it automatically

Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.

See how Auto-Revoking works →
Get Ultimate
Back to Exploits