Two-Day-Old Contract Upgrade Drains Gym Network of $2.1 Million on BSC
Gym Network, a BNB Chain yield aggregator built on top of Alpaca Finance, lost $2.1 million after an attacker exploited a feature the team had only just deployed, triggering a sell-off that crashed the price of its GYMNET token.
The team addressed the incident in an official statement, saying the underlying issue had already been patched and that it intended to pursue recovery of the stolen funds. The project had cleared two separate security audits just the previous month, making the timing of the flaw notable.

How the exploit worked
Two days before the attack, Gym Network deployed an updated Single Pool Contract that introduced a new "Claim and Pool" function. According to Peckshield, the added code failed to verify the calling contract, allowing an attacker to inflate their recorded balance without ever making a real deposit. Beosin corroborated the finding.
In effect, the bug let the attacker register fabricated deposits that the contract treated as legitimate despite no tokens actually changing hands. The attacker then simply withdrew against those falsely credited balances.
Tracing the funds
- Exploiter's address: 0xb2c035eee03b821cbe78644e5da8b8eaa711d2e5
- Sample exploit transaction: 0x8432c1c6613995eeea8a3ae2cfeb9577913db6b7b35dbe26a8c56c02066096e6
The attacker's initial funding was routed through Tornado Cash. Once the stolen GYMNET was in hand, the exploit contracts converted it into roughly 7,500 BNB in total, which then moved in three directions:
- About 2,000 BNB (~$570K) was sent back into Tornado Cash.
- About 3,000 BNB (~$855K) stayed parked in the attacker's BSC wallet.
- About 2,500 BNB was swapped for roughly 387 ETH (~$700K) and bridged to an Ethereum address under the attacker's control.
Gym Network moved quickly to identify the root cause publicly, posting an explanation of the vulnerability to its Telegram community shortly after the attack.
GYMNET's price fell by roughly 90% as the attacker liquidated the stolen tokens, though it has since recovered to about 70% of its pre-hack level.

Both Certik and Peckshield had signed off on the project in May — reviews that predated the vulnerable code, which was only introduced two days before the exploit.
Wider context
The incident adds to a recurring pattern on BNB Chain, where low barriers to launching projects have produced a steady supply of thinly secured protocols, some of which have been exploited more than once. It also lands at a moment when Binance is facing pressure from several directions: earlier that week it was reported that the SEC was investigating whether the original launch of BNB amounted to an unregistered securities sale, and Reuters published an investigative piece describing Binance as a hub for hackers, fraudsters, and drug traffickers. Binance pushed back by releasing email correspondence it says shows the Reuters journalists declined to share information the exchange needed to investigate the allegations. The episode also follows closely behind the collapse of Luna and UST, which had already hardened skepticism toward the industry among critics and mainstream outlets alike.
Get new scam files the moment we publish them — usually 2–3 emails a week.