CryptoReal
CASE FILE — Jun 13, 2023

Abandoned Atlantis Loans Loses $2.5M to a Governance Takeover on BSC

Nearly a week after the initial breach, additional funds were siphoned out of Atlantis Loans, pushing total losses to $2.5 million, according to figures from Peckshield. The first wave of the attack had already cost former users close to $1 million, as reported at the time.

Atlantis Loans had run as a lending protocol on BNB Smart Chain until its developers walked away from the project in early April. The team explained the decision in a Medium post, saying they could no longer afford to keep maintaining the platform and adding: "we believe that discontinuing our services is in the best interest of our users and the protection of their funds."

Despite the shutdown announcement, the protocol's contracts stayed live — the front-end UI had reportedly been paid up two years in advance. The same post noted that "the only way to make changes or turn things off will have to be done through the governance," a detail that would later prove significant.

Credit for identifying the incident goes to Beosin and Numen Cyber.

An earlier attempt to exploit the governance system on April 12 had failed to pass. With the project effectively deserted, a later governance proposal — number 52, published on June 7 — drew little attention.

Sums referenced in this case file

The attacker got that proposal pushed through and approved, gaining control of Atlantis Loans' token contracts. They then upgraded those contracts with malicious logic of their own, enabling transfers of tokens from any wallet that still held active approvals for Atlantis. Numen Cyber published a detailed thread breaking down exactly how the proposal was carried out.

Beosin compiled a full list of contracts users should revoke approvals for.

Attacker's address: 0xEADe071FF23bceF312deC938eCE29f7da62CF45b

The attacker's initial funding came from Binance on Ethereum.

Governance-based attacks have varied widely in scope and impact recently. The month before, Tornado Cash's governance was hijacked after an attacker slipped malicious code into what looked like a routine proposal. The year before that, Beanstalk lost $181 million to a flash-loan-powered governance attack made possible by the absence of any execution delay. And in March, Swerve — another abandoned Curve fork — was targeted through governance too, though unsuccessfully: a proposal there sought to redirect $1.3 million remaining in its DAI-USDC-USDT pool to the attacker's address, but they couldn't gather enough tokens to force the vote through.

This incident is a reminder both to revoke unused token approvals and to keep monitoring governance activity even on projects that look defunct.

Atlantis LoansBSC
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.