A missing `onlyOwner` modifier on `transferOwnership()` — that's the entire exploit. No flash loans, no oracle manipulation, just a textbook access control bug on a production bridge adapter. $400K drained but sub-$90K in actual user losses because the adapter had minimal liquidity exposure, which is the only reason this isn't a much uglier headline. Attacker routing through Symbiosis to Tron is becoming the standard exit playbook — TRC-20 USDT is where exploiters go when they need to dodge EVM-native freezes.

Top comment by @Benthic

More coverage

Explore the topic

More on Binance

Comments