Backdoor Withdraw Function Lets DeFiLabs Drain $1.6M From BSC Stakers
On July 27, DeFiLabs, a BSC-based staking platform, walked off with $1.6 million belonging to its users through a hidden withdrawal function embedded in its staking contract. The project had marketed itself as an AI-managed decentralized finance platform offering a "secure, stable, high-yield" staking pool — language that, in hindsight, checked every box of generic crypto marketing without delivering on any of it.
Rug pulls involving small, obscure BSC projects are a recurring feature of that ecosystem. Typically the amounts lost run from a few thousand to a few hundred thousand dollars, the project's social accounts disappear, and a small pool of speculative users absorbs the loss without much fanfare. What stood out here was less the mechanism than the question of why meaningful sums are still flowing into these projects this late in the cycle, after much of retail has already stepped away.

Credit for the technical detection goes to Beosin and HashDit.
01The Mechanism
As is typical for low-effort BSC rugs, there was nothing technically sophisticated about how this played out. The vPoolv6 contract contained a function called withdrawFunds, which gave a designated funder address the ability to pull all user deposits out of the contract at will.
The assets drained spanned several tokens, with BSC-USD making up the bulk of it, alongside Cake, wrapped BTC, wrapped ETH, and BUSD.
Exploiter address: 0xee08d6c3a983eb22d7137022f0e9f5e7d4cf0be2
Rug contract: 0xdEDbd1804569F369e33e453Ee311F0F97dCd0Bde
Sample transaction: 0xcd255e0d…
Consolidation address holding the $1.6M: 0x53ccFbC90A3fCDAfe9a2a50F798bEE7CcB5461b6
02Audited, But Not Where It Mattered
DeFiLabs had in fact been reviewed by two firms: Certik, which had already flagged centralization risk (effectively, the potential for exactly this kind of rug), and Cyberscope. Neither audit, however, covered the vPoolv6 contract — despite both reviews taking place after that contract had already been published on-chain.
03The Team's Response
Following the drain, DeFiLabs issued a statement across Twitter and Telegram, framing the situation as routine maintenance gone wrong:
[the] platform is currently undergoing maintenance and updates. Unfortunately, we encountered an unexpected issue during this process. To ensure the safety of your assets and smooth operations, we have decided to temporarily suspend staking operations.

Notably, the statement referenced paused withdrawals but made no mention of the staking contract having been drained. The team said an update would follow within 48 hours.
Two months prior, DeFiLabs had itself published a "RISK WARNING!!" notice on Medium, ostensibly to help users avoid interacting with anything other than the official contract — the same contract that ultimately contained the backdoor.
04Part of a Broader Pattern
This incident followed closely on the heels of another BSC rug, the $2.36 million GMETA loss from the previous week. According to BlockSec's MetaSleuth tracking, proceeds from one rug pull are frequently funneled directly into the next project's liquidity pool or used to inflate a new token's price.
The recurrence of near-identical exploits — the same bug reused across different protocols, centralized platforms losing large sums to compromised keys, and a steady drumbeat of small BSC project failures appearing every few days — has given the space a sense of déjà vu reminiscent of 2021's excesses.
Get new scam files the moment we publish them — usually 2–3 emails a week.