Compromised Deployer Key Lets Attacker Mint 60 Trillion aBNBc, Helio Money Users Exploit the Chaos for Millions More
An attacker illegitimately minted 60 trillion units of aBNBc, Ankr's BNB-staking receipt token — a quantity that, at face value, would theoretically be worth roughly $18 quadrillion, more than global GDP combined. Because available liquidity for aBNBc came nowhere close to supporting that figure, the attacker's actual take was limited to about $5 million.
Ankr confirmed the incident publicly, stating that users' underlying staked assets remained safe and promising a reissuance of aBNBc based on a snapshot. That, however, was not the end of the fallout.

(Credit for early detection: BlockSec and Peckshield.)
aBNBc functions as a reward-bearing receipt for BNB staked through Ankr on BNB Smart Chain. The root cause traced back to a compromised private key belonging to Ankr's BSC deployer address, likely obtained through a phishing operation.
Using the compromised deployer account, the attacker pushed a malicious replacement for the aBNBc token contract, then upgraded the live implementation to point to it. Buried in the new code was a previously nonexistent function (selector 0x3b3a5522) that skipped caller verification entirely, letting anyone — including the attacker — mint aBNBc straight to their own wallet.
Exploiter's address: 0xf3a465c9fa6663ff50794c698f600faa4b05c777
Compromised Ankr deployer address: 0x2ffc59d32a524611bb891cab759112a51f9e33c0
Sample mint transaction (aBNBc to exploiter): 0xe367d05e…
Deployer-to-exploiter funding transaction: 0xeb617798…
Despite minting an astronomical token supply, thin on-chain liquidity capped what the attacker could actually extract — around $5 million, pulled by draining PancakeSwap's aBNB-related pools. Most of those proceeds were bridged over to Ethereum, where the attacker began routing them through Tornado Cash.
Once news of the publicly exploitable infinite-mint bug spread, opportunistic copycats piled in — several of whom now rank among the largest holders of an aBNBc token that had, by then, lost all value.
One of these opportunists actually walked away with roughly three times what the original exploiter earned. Given the speed and recent funding pattern of the wallet involved, it's plausible this was the same actor operating under a second address.
That wallet — 0x8d11f5b4d351396ce41813dce5a32962aa48e217 — bought up large volumes of the collapsing aBNBc from PancakeSwap and carried it over to the stablecoin platform Helio Money. Before Helio's price oracle updated to reflect the crash, the user borrowed 16 million HAY against the still-mispriced aBNBc collateral, netting a profit of $15.5 million. A second account repeated the same method, pocketing about $3.5 million.

The resulting strain caused Helio's HAY stablecoin to depeg, trading around $0.62 at the time. Helio said affected users would be made whole.
Notably, both Peckshield's and Beosin's prior audits had flagged the risk posed by Ankr's privileged accounts — marked "Confirmed" and "Acknowledged" respectively — yet the issues were never remediated. The consequences of that inaction ultimately spilled over onto Helio as collateral damage.
Binance CEO CZ offered a summary of the situation:
"Possible hacks on Ankr and Hay. Initial analysis is developer private key was hacked, and the hacker updated the smart contract to a more malicious one. Binance paused withdrawals a few hrs ago. Also froze about $3m that hackers move to our CEX."
Get new scam files the moment we publish them — usually 2–3 emails a week.