Less than a day after Griffin AI’s GAIN token launched on Binance’s Alpha platform and multiple centralized exchanges, the project suffered a severe cross‑chain exploit tied to its LayerZero bridge configuration. An attacker (or someone with access to an admin key) set up an unauthorized LayerZero peer pointing to a fake Ethereum contract, then used that trusted endpoint to mint 5 billion unauthorized GAIN tokens on BNB Chain, expanding supply from the intended 1 billion cap to roughly 5.3 billion. Blockchain data and post‑mortems indicate the exploiter dumped only about 147.5 million GAIN (~2.8% of the new supply) via PancakeSwap and OTC trades, netting around $3–4 million before liquidity and price collapsed, while the remaining ~97% of the illicitly minted tokens stayed in the attacker’s wallet and hung over the market as massive overhang.
The core failure lay in admin privileges over cross‑chain configuration rather than a direct bug in the token contract itself. Griffin AI used LayerZero for bridging between Ethereum and BNB Chain; by compromising or misusing an admin externally owned account, the attacker called functions like setPeer to make a malicious Ethereum contract appear as a legitimate cross‑chain peer. That let the bridge treat fake Ethereum‑side GAIN as real and mint corresponding tokens on BNB Chain without backing. On‑chain investigators including GoPlus, CertiK, PeckShield, and others traced the flow: about 147.5 million GAIN were swapped for roughly 2,955 BNB, bridged to other networks (Ethereum, Solana, Base, Arbitrum), converted to ETH, and partially laundered through Tornado Cash. The event wiped out roughly 85–90% of GAIN’s price and tens of millions in market cap within a day of launch.
In public statements, Griffin AI CEO Oliver Feldmeier acknowledged that the attack stemmed from a misconfigured LayerZero setup and compromised key and took full responsibility for the failure of operational security around admin controls. The team paused GAIN trading on BNB Chain, coordinated with centralized exchanges to halt trading, deposits, and withdrawals, and involved law enforcement and security partners, though no recovery of funds has been reported. The incident added to growing concerns around cross‑chain bridge security and the concentration of power in admin keys: despite prior auditing of the GAIN token contract, analysts noted that the critical risk emerged from post‑deployment configuration and key management rather than core contract logic, fueling community debate over whether this was purely an external hack or potentially aided by insider mismanagement.
"entities":["Griffin AI","GAIN","$GAIN","GriffinAI","LayerZero","LayerZero Labs","Binance","Binance Alpha","BNB Chain","Ethereum","PancakeSwap","GoPlus Security","CertiK","PeckShield","deBridge","Tornado Cash","KuCoin","HTX","MEXC","Gate.io","OKX","Bitget","Oliver Feldmeier"]}'}Note: The JSON appears malformed at the end. Here's the corrected version:json
{"brief":"Less than a day after Griffin AI’s GAIN token launched on Binance’s Alpha platform and multiple centralized exchanges, the project suffered a severe cross‑chain exploit tied to its LayerZero bridge configuration. An attacker (or someone with access to an admin key) set up an unauthorized LayerZero peer pointing to a fake Ethereum contract, then used that trusted endpoint to mint 5 billion unauthorized GAIN tokens on BNB Chain, expanding supply from the intended 1 billion cap to roughly 5.3 billion. Blockchain data and post‑mortems indicate the exploiter dumped only about 147.5 million GAIN (~2.8% of the new supply) via PancakeSwap and OTC trades, netting around $3–4 million before liquidity and price collapsed, while the remaining ~97% of the illicitly minted tokens stayed in the attacker’s wallet and hung over the market as massive overhang.\n\nThe core failure lay in admin privileges over cross‑chain configuration rather than a direct bug in the token contract itself. Griffin AI used LayerZero for bridging between Ethereum and BNB Chain; by compromising or misusing an admin externally owned account, the attacker called functions like setPeer to make a malicious Ethereum contract appear as a legitimate cross‑chain peer. That let the bridge treat fake Ethereum‑side GAIN as real and mint corresponding tokens on BNB Chain without backing. On‑chain investigators including GoPlus, CertiK, PeckShield, and others traced the flow: about 147.5 million GAIN were swapped for roughly 2,955 BNB, bridged to other networks (Ethereum, Solana, Base, Arbitrum), converted to ETH, and partially laundered through Tornado Cash. The event wiped out roughly 85–90% of GAIN’s price and tens of millions in market cap within a day of launch.\n\nIn public statements, Griffin AI CEO Oliver Feldmeier acknowledged that the attack stemmed from a misconfigured LayerZero setup and compromised key and took full responsibility for the failure of operational security around admin controls. The team paused GAIN trading on BNB Chain, coordinated with centralized exchanges to halt trading, deposits, and withdrawals, and involved law enforcement and security partners, though no recovery of funds has been reported. The incident added to growing concerns around cross‑chain bridge security and the concentration of power in admin keys: despite prior auditing of the GAIN token contract, analysts noted that the critical risk emerged from post‑deployment configuration and key management rather than core contract logic, fueling community debate over whether this was purely an external hack or potentially aided by insider mismanagement.","entities":["Griffin AI","GAIN","$GAIN","GriffinAI","LayerZero","LayerZero Labs","Binance","Binance Alpha","BNB Chain","Ethereum","PancakeSwap","GoPlus Security","CertiK","PeckShield","deBridge","Tornado Cash","KuCoin","HTX","MEXC","Gate.io","OKX","Bitget","Oliver Feldmeier"]}
✨ AI-generated background, compiled from web sources — not editorial content.