A decentralized payment project on Binance Smart Chain (BSC) called GANA Payment was exploited at around 5:00 AM UTC on Thursday, resulting in losses exceeding $3.1 million, according to blockchain researcher ZachXBT.  The crypto investigator’s findings showed that the attacker used a flaw in the project’s smart contract to steal tokens. They then moved them […]A decentralized payment project on Binance Smart Chain (BSC) called GANA Payment was exploited at around 5:00 AM UTC on Thursday, resulting in losses exceeding $3.1 million, according to blockchain researcher ZachXBT.  The crypto investigator’s findings showed that the attacker used a flaw in the project’s smart contract to steal tokens. They then moved them […]

GANA Payment exploited for more than $3.1 million

2025/11/20 19:42
4 min read

A decentralized payment project on Binance Smart Chain (BSC) called GANA Payment was exploited at around 5:00 AM UTC on Thursday, resulting in losses exceeding $3.1 million, according to blockchain researcher ZachXBT. 

The crypto investigator’s findings showed that the attacker used a flaw in the project’s smart contract to steal tokens. They then moved them through Tornado Cash and other networks to set up money laundering operations.

“GANA’s interaction contract has been targeted by an external attack, resulting in unauthorized asset theft…We will continue to provide updates on the investigation progress and subsequent actions through official channels,” the DeFi platform wrote on X earlier today.

Several cybersecurity platforms on X, including OnChain Lens, reported that the exploit began when the attacker transferred 1,140 BNB, valued at approximately $1.04 million, into Tornado Cash on BSC. 

The stolen assets were subsequently bridged to Ethereum, where another 346 ETH, worth $1.05 million, was deposited into the crypto mixer purportedly for laundering.

Blockchain records shared by ZachXBT show the Ethereum address used for laundering was 0x7a503e3ab9433ebf13afb4f7f1793c25733b3cca. The original theft addresses on BSC were identified as 0x2e8a…aae5c38 and 0xd10e…cc8fa4d.

Hacker exploited GANA’s ‘unstake function’ to steal coins

According to Web3 security firm HashDit, the ownership of the exploited contract had been altered, which the hacker used to manipulate reward rates and invoke the unstake function, receiving more GANA tokens than intended. 

The perpetrator then rapidly sold the tokens on decentralized exchanges, significantly devaluing the project’s currency. A total amount of 346 ETH held in the Ethereum address remained dormant for several hours. 

However, beginning an hour ago, the hacker resumed laundering the funds through Tornado Cash in incremental batches of 1 ETH, 10 ETH, and 100 ETH, a method used by thieves during DeFi attacks to “shake-off” security researchers’ trail of stolen funds.

GANA Payment is a relatively small-scale payment token project built around the BEP-20 GANA token. Its operations are decentralized and use liquidity pools and exchanges, but Cryptopolitan has not found any publicly available technical documentation. 

The project, which launched in early November, has yet to publish formal audits or detailed security analyses. In the aftermath of the hack, data from GeckoTerminal showed that GANA’s token value dropped more than 90%.

DeFi exploits on BSC, Ethereum cooled in October

According to DefiLlama’s hack tracker, smaller BSC-based projects have collectively lost over $100 million in 2025 alone. The hack on GANA has taken the tally to almost $10 million in the last two months, including network breaches on OlaXBT, Evoq Finance, Seedify and GriffinAI.

Cryptopolitan reported in October that total losses from hacks amounted to just $18.18 million in about 15 incidents, an 85.7% drop from September’s $127.06 million. Major incidents that took place during the month included hacks at Garden Finance, Typus Finance, and Abracadabra, which together accounted for $16.2 million in stolen funds. 

Abracadabra, a decentralized lending protocol and maker of the Magic Internet Money (MIM) stablecoin, suffered a $1.8 million loss when attackers used flaws in how the contract handled actions within the same transaction. 

Typus Finance lost $3.4 million due to access control weaknesses in its custom price oracle, while Garden Finance experienced an $11 million loss through a single solver connected to several blockchain networks.

This month, Balancer was hit with one of the largest DeFi hacks of 2025, where wrapped ETH and other assets from multiple networks were swindled for several hours. Blockchain investigators had estimated losses of about $70 million, but when the network’s developers took back control, the bleeding had gone north of $116 million. 

The following day, multi-chain lending protocol Moonwell was exploited via flawed oracle data, losing around $1 million. The attacker took advantage of price discrepancies to borrow and trade specific wrapped ETH assets, pocketing 295 ETH.

Per DefiLlama data, cross-chain bridge hacks in 2025 had resulted in over $1.5 billion in stolen funds by mid-2025, while reentrancy bugs accounted for $325 million in losses, particularly from older or forked contracts. Oracle manipulation accounted for 13% of attacks, while liquidity pool drains caused $103 million in stolen assets. 

The smartest crypto minds already read our newsletter. Want in? Join them.

Market Opportunity
Moonveil Logo
Moonveil Price(MORE)
$0.0006335
$0.0006335$0.0006335
-3.00%
USD
Moonveil (MORE) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Strive and Semler Scientific to Merge in All-Stock Deal, Creating Bitcoin Treasury Powerhouse

Strive and Semler Scientific to Merge in All-Stock Deal, Creating Bitcoin Treasury Powerhouse

Strive, Inc. has entered into a definitive agreement to acquire healthcare infrastructure firm Semler Scientific, Inc. in an all-stock transaction. In an announcement, the firm said the merger represents an approximately 210% premium, equivalent to about $90.52 per share, based on the closing prices of both companies on September 19. Under the terms of the agreement, each common share of Semler Scientific will be exchanged for 21.05 Class A common shares of Strive. The transaction has been unanimously approved by the boards of directors of both companies and remains subject to customary closing conditions. Bitcoin Treasury Strengthened with $675 Million Purchase In conjunction with the merger announcement, Strive reveals it has purchased 5,816 bitcoin at an average price of $116,047 per bitcoin, totaling $675 million. This acquisition increases Strive’s total holdings to 5,886 bitcoin. Following the merger, the combined company would own more than 10,900 bitcoin, excluding any additional purchases funded through future capital raises. Earlier this year, Semler Scientific said it is planning to accumulate 10,000 Bitcoin and targets 105,000 Bitcoin by 2027. The company appointed BTC expert Joe Burnett as Director of Bitcoin Strategy to help lead its ambitious plans Future Plans for Diagnostics Business While bitcoin holdings remain central to the merger, the combined company also intends to explore options to monetize or distribute Semler Scientific’s profitable diagnostics business. The strategy includes expanding into preventative diagnostics, focusing on early detection of chronic diseases and broader wellness initiatives. This dual approach aims to balance financial growth through bitcoin accumulation with mission-driven expansion in healthcare. Strive’s management and board of directors will continue to lead the merged entity, with Semler Scientific’s Executive Chairman Eric Semler joining the board post-closing. Leadership Views on the Transaction “This merger cements Strive’s position as a top Bitcoin treasury company. We believe our capital structure and strategies position us to outperform bitcoin over the long run,” said Matt Cole, Chairman and CEO of Strive. “This merger creates significant value for our stockholders by delivering a substantial premium and direct participation in one of the most innovative bitcoin strategies in the public markets,” said Eric Semler from Semler Scientific, Inc. With unanimous board approval and strong alignment on strategy, the merger is positioned to create a scaled, innovative bitcoin acquisition platform while expanding into preventative healthcare
Share
CryptoNews2025/09/22 22:54
Milyar Dolarları Yöneten Şirket, Onchain Verilerine Göre Bu Altcoini Topluyor Olabilir!

Milyar Dolarları Yöneten Şirket, Onchain Verilerine Göre Bu Altcoini Topluyor Olabilir!

Galaxy Digital bağlantılı adreslerin ASTER altcoinindeki hareketliliği dikkat çekiyor. Onchain analiz platformlarının aktardığına göre, Galaxy Digital ile ilişkilendirilen bir adres son 24 saat içerisinde borsalardan 13 milyon ASTER token daha çekti. Bu miktar, güncel fiyatlarla yaklaşık 29.12 milyon dolara karşılık geliyor. Son işlemle birlikte bu adresin toplam ASTER bakiyesi 46 milyona ulaşmış durumda. Tokenlerin toplam […] Kaynak: Bitcoinsistemi.com
Share
Coinstats2025/09/25 04:56
Rizz Network Lands $5M Capital Commitment from Nimbus Capital to Drive Next-Generation AI-DePIN Rizz Wireless Rollout

Rizz Network Lands $5M Capital Commitment from Nimbus Capital to Drive Next-Generation AI-DePIN Rizz Wireless Rollout

Rizz Network Inc. (“Rizz” or the “Company”), the issuer of RZTO, today announced that Nimbus Capital has entered into a strategic investment commitment in RZTO
Share
Cryptodaily2026/02/16 18:54