CryptoReal
CASE FILE — Jun 24, 2021

Tipped Off and Powerless — How StableMagnet's $27M Rugpull Played Out

Hours before StableMagnet collapsed, an anonymous tipster reached out to warn that the project was about to rug its users. The claim could not be independently verified, which left little room to act: publishing an unconfirmed accusation risked spreading unfounded fear about a project that might have been legitimate, and there was no practical way to whitehat the funds pre-emptively. The only option was to wait and watch.

That wait ended with roughly $27 million drained, a figure still climbing as wallets that never revoked their approvals to StableMagnet continue to be emptied. Anyone still exposed is urged to strip StableMagnet's permissions using the BSC Token Approval Checker.

Looking back, the tip lines up with concerns raised earlier about the project, echoing suspicions that had already been circulating. It also puts a harsh spotlight on the project's auditor: Techrate's sign-off should not have been treated as a guarantee of safety.

How the exploit worked

The rug began with a single transaction that pulled an initial $22.2 million in stablecoins out of the StableMagnet 3Pool, a total that has since grown to the current $27 million estimate.

The mechanism relied on an unverified library contract. As Rugdoc explained, block explorers like Etherscan and BscScan do not verify the source code of linked libraries — only of the primary contract. That gap let the deployer swap in a library whose actual bytecode diverged completely from whatever source was presented publicly.

In this case, the unverified SwapUtil library — deployed at 0xE25d05777BB4bD0FD0Ca1297C434e612803eaA9a — did double duty: it drained every liquidity pair on the platform, and separately pulled additional tokens from any wallet that had granted StableMagnet a spending approval. Notably, at least two other still-operating projects, Dopple and StableGaj, are built on the same underlying codebase and carry the same kind of unverified SwapUtils library.

Laundering the proceeds

Sums referenced in this case file

Once stolen, the funds were fragmented across numerous wallets and funneled into Binance, apparently to bridge from BSC over to Ethereum. From there they were withdrawn quickly, converted out of centralized USDT, and moved into decentralized DAI — a sequence that suggests the attackers had an exit plan mapped out well in advance. The same BUSD-to-USDT-to-DAI routing was observed repeated across multiple separate addresses, raising questions about how rigorously Binance's KYC checks were applied here, despite the exchange's public assurances.

Traceable addresses in the flow include:

Ongoing exposure

Because the exploit also targeted wallets with standing approvals, the damage did not end with the initial drain. At the time of reporting, over 1,000 addresses still held non-zero allowances to the StableMagnet contract, meaning further losses were expected as the attackers continued to sweep them. The incident debuted at number 8 on the rekt leaderboard, a ranking likely to shift as the total keeps rising.

A pattern of prior rugs

The same anonymous source claimed this was not an isolated act — that the group behind StableMagnet had also been responsible for earlier rugpulls, specifically naming the Moon Here token (0xf84c682279E6B687Fc3449954e25377ECC1A59f9) and the Wen Moon token (0x16a4a0bb3c8b3dde8459f192b9ae09cad7b95a70).

The source further alleged that "Techrate audited the Github, but not the deployed contract" — meaning the audited repository and the code actually running on-chain were not the same thing. Techrate is reported to have been alerted to the unfolding rugpull and to have taken no action in response. A review of the roster of projects Techrate has audited offers some sense of the firm's track record.

This episode stands out among documented rugpulls for its layered approach: a known group allegedly draining not just the protocol's own liquidity but also the wallets of individual users who trusted it, before routing the proceeds into DAI for cover. It is also not the first case where questions have been raised about an auditor's role, and at least two other major hacks are reportedly under investigation over similar concerns about the auditor's involvement. The broader lesson stands regardless: an audit label should not substitute for independent due diligence.

BSCStableMagnet
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.