CryptoDAOGlobal suffered an access control flaw allowing an attacker to drain 167,200 $PRO tokens worth $52,000.
Security & Exploits ·
An access control vulnerability in CryptoDAOGlobal's smart contract on BNB Chain enabled an attacker to drain 167,200 $PRO tokens valued at approximately $52,000 on July 28. The exploit leveraged a flaw in the contract's exec function, which lacked access controls and could be invoked by any caller. The attacker executed the function repeatedly within a single transaction, each time swapping 50 $PRO into $USDT.
Through multiple successive calls, the attacker artificially inflated the price of the $PRO/$USDT trading pair before converting remaining holdings into stablecoins. All stolen tokens were ultimately swapped to $USDT and transferred to addresses controlled through the vulnerable contract. The attack succeeded because the exec function contained no permission checks to restrict who could call it.
The incident highlights the ongoing risk of insufficient access controls in decentralized finance contracts. No information has been disclosed about whether CryptoDAOGlobal has deployed a patch, initiated a recovery process, or announced compensation measures for affected parties.