CryptoReal
CASE FILE — Jun 10, 2022

Two-Day-Old Contract Upgrade Drains Gym Network of $2.1 Million on BSC

Gym Network, a BNB Chain yield aggregator built on top of Alpaca Finance, lost $2.1 million after an attacker exploited a feature the team had only just deployed, triggering a sell-off that crashed the price of its GYMNET token.

The team addressed the incident in an official statement, saying the underlying issue had already been patched and that it intended to pursue recovery of the stolen funds. The project had cleared two separate security audits just the previous month, making the timing of the flaw notable.

How the exploit worked

Two days before the attack, Gym Network deployed an updated Single Pool Contract that introduced a new "Claim and Pool" function. According to Peckshield, the added code failed to verify the calling contract, allowing an attacker to inflate their recorded balance without ever making a real deposit. Beosin corroborated the finding.

In effect, the bug let the attacker register fabricated deposits that the contract treated as legitimate despite no tokens actually changing hands. The attacker then simply withdrew against those falsely credited balances.

Tracing the funds

Sums referenced in this case file

The attacker's initial funding was routed through Tornado Cash. Once the stolen GYMNET was in hand, the exploit contracts converted it into roughly 7,500 BNB in total, which then moved in three directions:

  • About 2,000 BNB (~$570K) was sent back into Tornado Cash.
  • About 3,000 BNB (~$855K) stayed parked in the attacker's BSC wallet.
  • About 2,500 BNB was swapped for roughly 387 ETH (~$700K) and bridged to an Ethereum address under the attacker's control.

Gym Network moved quickly to identify the root cause publicly, posting an explanation of the vulnerability to its Telegram community shortly after the attack.

GYMNET's price fell by roughly 90% as the attacker liquidated the stolen tokens, though it has since recovered to about 70% of its pre-hack level.

Both Certik and Peckshield had signed off on the project in May — reviews that predated the vulnerable code, which was only introduced two days before the exploit.

Wider context

The incident adds to a recurring pattern on BNB Chain, where low barriers to launching projects have produced a steady supply of thinly secured protocols, some of which have been exploited more than once. It also lands at a moment when Binance is facing pressure from several directions: earlier that week it was reported that the SEC was investigating whether the original launch of BNB amounted to an unregistered securities sale, and Reuters published an investigative piece describing Binance as a hub for hackers, fraudsters, and drug traffickers. Binance pushed back by releasing email correspondence it says shows the Reuters journalists declined to share information the exchange needed to investigate the allegations. The episode also follows closely behind the collapse of Luna and UST, which had already hardened skepticism toward the industry among critics and mainstream outlets alike.

BSCGym Network
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.