Corezcat and GameStopfun rug pulls exploited external balanceOf logic to drain $93K combined.
Security & Exploits ·
Two separate incidents—Corezcat and GameStopfun—resulted in combined losses of $93K through exploitation of external balanceOf logic. The attacks leveraged flawed token balance verification mechanisms to drain user funds. Both projects were affected by the same class of vulnerability, in which attackers manipulated how smart contracts checked account balances, bypassing intended security checks.
The vulnerability centers on how these protocols handled external calls to verify token balances. Rather than maintaining internal balance records, the contracts relied on external logic that attackers could manipulate or spoof. This design flaw allowed unauthorized draining of liquidity before detection. The pattern reflects a broader category of rug-pull mechanics in which insiders or attackers exploit technical control over funds to abandon or collapse a project.
Details on the specific timeline, affected token contracts, and recovery status remain unclear from available reporting. It is not specified whether either project team was involved in the exploitation or whether these were attacks by external actors against the protocol itself.