CryptoReal
CASE FILE — Mar 29, 2023

Safemoon Upgrade Bug Lets Attacker Drain $8.9M From SFM/BNB Liquidity Pool

Safemoon lost $8.9 million worth of liquidity-pool funds on March 28, 2023, after a bug introduced in the project's most recent smart contract upgrade allowed an attacker to drain its SFM/BNB pool. The incident was confirmed by the project and by CEO John Karony on Twitter, with replies disabled on both announcement tweets.

Roughly six hours before the attack, the Safemoon: Deployer address had upgraded the SFM token contract to a new implementation. That upgrade left the contract's burn() function publicly callable, meaning anyone could burn SFM tokens out of any address without permission — including the tokens sitting inside the SFM:BNB liquidity pool itself.

The attacker used this to burn a large amount of SFM held in the pool, artificially inflating the token's price within it. They then sold SFM they had acquired beforehand into the now-distorted pool, draining its BNB side for a profit of roughly 28,000 BNB, worth about $8.9 million. The exploit transaction is recorded on-chain (0x48e52a12…), with the funds landing at attacker address 0x286e0993….

A few hours later, the attacker sent an on-chain message to the Safemoon: Deployer address, describing themselves as an MEV bot operator who had accidentally frontrun an attack targeting Safemoon and offering to return the funds if a secure communication channel could be established. Past on-chain activity tied to the address, however, suggests the sender is not the good-faith actor the message implies. The attacker also reached out separately to negotiate the return of funds. Most of the stolen BNB has since been moved to a separate address (0x237D…), where it remained as of this writing.

Security researchers at PeckShield and MoonMark are credited with flagging the exploit. PeckShield raised the possibility — charitably, or simply as the most likely explanation — that the deployer's admin keys had been leaked or phished rather than the bug being deliberately planted.

The incident adds to a long list of controversies surrounding Safemoon since its 2021 launch. The project was labeled a pump-and-dump scheme early on, later became the subject of a class-action lawsuit against Safemoon LLC and associated parties, and was the focus of a multi-part investigation by Coffeezilla. It was especially popular among TikTok-driven retail investors during the Binance Smart Chain hype cycle of spring 2021, marketing itself as un-ruggable thanks to a liquidity pool that was topped up with every token transfer — a mechanism that was itself criticized as a form of ponzinomics, since the transfer fees discouraged holders from ever selling.

Whether this was a botched insider rug attempt or simply the result of careless engineering, the episode does little to restore confidence in a project that already carried a poor reputation, even among the community members who continue to hold SFM.

BSCSafemoon
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.