Evoq Finance contracts were attacked, losing around $420,000
TechFlame
2025-09-10 15:58
TechFlame2025-09-10 15:58
English
According to TechFlame, according to GoPlus Security monitoring, Evoq Finance's smart contract on BNB Chain has been attacked. The attackers stole the owner's account, transferred ownership to themselves, then upgraded the contract to a malicious version, stealing approximately $42 million from the agreement and user approvals. Users are required to immediately revoke token approval for the contract 0xF9C74A65B04C73B911879DB0131616C556A626BE to prevent further losses. Project parties should take care to protect high-privilege accounts using multiple signatures and regular key rotation. Attack Overview: The attackers appear to have stolen the owner's account's private key (0xF08D1C) and used TransferOwnership to transfer ownership to their address (0x7B416F). The proxy contract is then upgraded to drain the funds from the contract and approved user accounts.