Bankroll Network Hack
Check if your address is affected.
Bankroll Network offered dividend-style DeFi products, including Stack contracts where users deposited tokens and earned a share of the fees paid by other users. It ran on several blockchains, including Ethereum and BNB Chain, but the project was abandoned years ago. The old contracts stayed on-chain, however, and so did the token approvals users had given them. On 19 June 2025, an attacker started exploiting a bug in the way these contracts kept track of each user's payouts.
The contracts were written with an old version of Solidity, the programming language used for these smart contracts, which does not stop a calculation from going below zero. By triggering such a calculation, the attacker could throw off the contracts' payout bookkeeping and use them to pull tokens from any wallet that still had an approval to them. About $35k was taken on Ethereum and BNB Chain. Security firm Blockaid spotted the attack as it happened and warned users to revoke their approvals as soon as possible.
Nobody maintains these contracts anymore, so they will not be fixed or paused and will stay dangerous for as long as approvals to them exist. If you ever used Bankroll Network on Ethereum or BNB Chain, check your wallet and revoke any approvals to its contracts. This incident shows why old approvals matter: a project can be long gone while its contracts, and the permissions you gave them, are still active.
Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.
Next time, revoke it automatically
Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.
See how Auto-Revoking works →