Forged Deposit Proofs Let a Hacker Mint $586M on BNB's Legacy Bridge
On October 7, 2022, BSC Token Hub — the bridge linking the original Binance Beacon Chain to BNB Chain (formerly BSC) — was exploited into minting two separate batches of 1 million BNB apiece straight into an attacker-controlled wallet, for a combined 2 million BNB. At the BNB price of $293 at the time, that put the theoretical total at $586 million, enough to rank third on rekt's leaderboard. In practice, only about $127 million of it made it off-chain to other networks before the attacker lost access to the remainder.
BNB Chain, then DeFi's third-largest layer-1 by TVL, detected "irregular activity" and halted the network for roughly eight hours. That pause locked ordinary users out of their own assets for its duration, including anyone who might have needed funds urgently or was at risk of liquidation. During the incident, Binance CEO Changpeng "CZ" Zhao posted, in a tweet he later deleted: "It's not about cash flow; it's crypto flow."

Per analysis from samczsun and FrankResearcher, the attacker forged deposit proofs referencing the legacy Beacon Chain to trick the bridge into minting BNB that had never actually been deposited. The two fraudulent mints executed at 18:26 UTC and 20:43 UTC, in one transaction and a second. The root cause was a flaw in the bridge's IAVL proof verification, which allowed the attacker to forge a proof referencing block 110217401, a block dating back to August 2020. All the minted BNB landed in a single exploiter wallet.
Samczsun summarized the underlying issue directly: "there was a bug in the way that the Binance Bridge verified proofs which could have allowed attackers to forge arbitrary messages. Fortunately, the attacker here only forged two messages, but the damage could have been far worse." (See the full thread for the technical breakdown.)
Rather than immediately dumping the stolen BNB — which would have tanked its price and drawn attention — the attacker deposited it as collateral on Venus Protocol, a lending platform on BSC. Venus was quick to note that its own contracts hadn't been compromised, though users did experience a spike in borrowing rates as liquidity was pulled from the platform. That laundering approach briefly convinced some observers that a large holder was simply repositioning funds, until unusually high-slippage swaps and Tether's move to blacklist some of the funds signaled something more serious.
Expecting Binance to eventually pause the chain, the attacker moved quickly to bridge assets elsewhere. SlowMist's tracing shows the attacker first supplied 900,000 BNB to Venus, borrowed roughly $147 million in stablecoins against it, and then routed those funds to Ethereum and various L2s, Fantom (an inflow that reportedly now accounts for more than 10% of that chain's TVL), Avalanche, and Polygon. SlowMist's table of the attacker's resulting holdings also shows roughly $6.5 million in USDT that Tether subsequently froze.
When BNB Chain validators halted the network about 90 minutes after the second fraudulent mint, the attacker still had roughly $430 million sitting on their BSC address — funds that became inaccessible once the chain stopped. SlowMist also noted the attacker's wallets had originally been funded through ChangeNOW, a centralized exchange.
In the aftermath, Binance's public messaging shifted into damage control. An official update asserted that "decentralised chains are not designed to be stopped" — a claim in tension with the fact that only 26 validators were active at the time, raising the question of how decentralized the chain actually was. The same update laid out next steps: governance votes on whether to freeze or burn the stolen funds, and plans to establish formal bug-bounty and whitehat-bounty programs, alongside a promise to grow the number of "community validators" as a move toward further decentralization.

Making the portion of funds that left the chain whole is, relative to Binance's scale, a comparatively small cost. CZ himself put a number on it, writing that "the current impact estimate is around $100m USD equivalent, about a quarter of the last BNB burn." He also distanced himself from the chain's engineering side, tweeting that he is "not that involved in the technical side of BNB Chain. Far less than Vitalik with ETH" — a framing that could be read as an attempt to redirect regulatory scrutiny elsewhere.
The episode leaves an awkward question hanging: if the chain could be halted this time, why not for the other BSC exploits rekt has covered previously? And what does this level of centralized control imply for how regulators will view BNB Chain going forward? There's a further concern, too — pausing a heavily used network sets a precedent that could matter far more once crypto underpins everyday transactions, where a halt might carry genuinely high stakes.
CZ's willingness to intervene in supposedly immutable systems isn't a new pattern: a 2019 clip shows him weighing a rollback of the Bitcoin network itself, acknowledging the "far reaching consequences" and risk of "destroying credibility," even though that plan never moved forward. Whether BNB Chain's standing in DeFi survives this incident intact remains to be seen — for now, it's another entry on the leaderboard.
Get new scam files the moment we publish them — usually 2–3 emails a week.