A $211M Flash Loan and a Broken Fee Function Drained New Gold Protocol for $2M
New Gold Protocol (NGP), a newly launched project on BNB Chain with roughly 299 followers on X, lost approximately $2 million on September 17 to an exploit combining a flash loan, price-oracle manipulation, and a flawed transfer function. The attack came just three days after the project posted that "security is non-negotiable."
01Detection and silence

Blockaid's monitoring systems flagged the incident first, describing "multiple malicious transactions targeting NGP on BSC" with an estimated $2 million drained. PeckShield corroborated the finding shortly after, confirming that the $NGP token, issued by @newgoldprotocol, had been exploited for roughly $2 million. Within about an hour, the token's price had fallen 88%, and the stolen funds were already moving through Tornado Cash.
NGP's official channels did not acknowledge the exploit. More than 24 hours after the loss, the project's X account had posted nothing about it and continued promoting its recent launch. Its Telegram group showed ordinary activity over the same period with no mention of the hack.
02How a $211 million flash loan produced a $2 million theft
The exploit rested on two design flaws: a getPrice() function that derived NGP's value directly from a single PancakeSwap pool's reserves, and a transfer function containing a self-defeating fee mechanism. Pricing a token off one DEX pool's reserves is a known weak point, since flash loans let an attacker distort those reserves cheaply and temporarily.
Per CertiK's analysis, the attacker borrowed a $211 million flash loan and used it to flood NGP's mainPair pool, crashing the NGP side of the reserves while inflating the USDT side. Blockaid noted that this pushed getPrice() to read NGP as essentially worthless, letting the attacker bypass the protocol's maxBuyAmountInUsdt purchase caps and acquire large token quantities.
The transfer function compounded the problem: according to CertiK, every sale deducted 35% from the pool's balance and then called sync() to reset the recorded reserves — a mechanism that turned each sell into a way to further corrupt the pool's own pricing.
Phalcon's review found the attacker had already accumulated NGP tokens beforehand across multiple accounts. Separately, researcher William Li noted that the burn address had been whitelisted from the buying limits, letting the attacker route purchases through it to sidestep the caps entirely. Having built up a position via the distorted pricing, the attacker then sold the entire holding at once, triggering the deduction-and-sync mechanism repeatedly. CertiK reported this collapsed the pool's NGP reserves from 477,000 tokens to 0.035 tokens — a roughly 13.6-million-fold reduction that effectively destroyed the pool's x*y=k invariant.
03Tracing the funds
The attacking wallet was first funded from Tornado Cash on September 10, in transaction 0x31b80cf3b477948fb47a03aa5ecb8a9e30b99840e59af8959e5797c1ea4cd3a3. The exploiter's BSC address was 0x0305ddd42887676ec593b39ace691b772eb3c876, and the attack executed in a single transaction, 0xc2066e0dff1a8a042057387d7356ad7ced76ab90904baa1e0b5ecbc2434df8e1, on September 17 at 7:02 PM UTC.

After the pool was drained, the stolen USDT was swapped for ETH and bridged back to Ethereum mainnet, arriving at 0x8618314270528e245fbbb6fba54e245bb61a8d47. From there, 444 ETH moved into Tornado Cash across roughly twenty separate deposits over about ten minutes, using standard denominations of 0.1, 1, 10, and 100 ETH — a methodical pattern suggesting familiarity with the mixing process rather than improvisation.
04An ambitious roadmap, an insecure launch
NGP's whitepaper laid out a multi-year plan whose five-year roadmap promised that "AI-powered contract auditing improves security" by 2026, alongside other features slated for the same year — a "native DEX with automated matching," Layer 2 testnets, and an "Aurora AI v2" system for automated fund management — as part of a broader vision reaching toward an "intelligent civilization" by 2030. Supporting documentation, meanwhile, was hosted in a public Google Drive folder rather than more conventional infrastructure.
None of those future ambitions prevented the project's actual 2025 launch from failing at basic price-feed security within days. More than 24 hours after the exploit, NGP's Telegram channel showed regular chat activity with zero mention of the $2 million loss, and the protocol's accounts issued no statement, damage assessment, or guidance to affected users.
Get new scam files the moment we publish them — usually 2–3 emails a week.