Ankr aBNBc exploit: what happened and how it ended
On 1 December 2022, an attacker compromised the deployer private key for Ankr's BNB liquid-staking token, replaced the aBNBc contract with malicious code and minted 60 trillion aBNBc across six transactions. The attacker swapped part of the unbacked supply through decentralised exchanges, draining liquidity and causing aBNBc's market price to collapse.
Ankr estimated the direct damage at about $5 million worth of BNB across liquidity pools. The number is not “five million BNB,” as the original breaking-news article stated. Ankr paused affected systems, coordinated trading halts, secured the contracts with a new key and took a snapshot at BNB Chain block 23,545,403.
| Item | Verified outcome |
|---|---|
| Root cause | Ankr's after-action report attributed the incident to a malicious former team member who combined social engineering and a supply-chain attack to compromise the deployer key. |
| Minted amount | 60 trillion aBNBc across six transactions, according to Ankr's token report. |
| Direct estimated damage | About $5 million worth of BNB across DEX liquidity pools. |
| Old tokens | aBNBc and aBNBb were discontinued and replaced by ankrBNB. |
| Initial recovery | Ankr created a recovery fund, airdropped ankrBNB or BNB to eligible snapshot holders and compensated affected protocol users in stages. |
| Later compensation account | In February 2023, Ankr said it had provided 100% compensation for users affected through 17 of 19 protocols, 50% relief for specified Stader and pStake pools, and approximately $30 million of compensation overall. |
Was this a smart-contract exploit?
Not in the usual sense of an outside attacker discovering a permissionless coding flaw. Ankr said the attacker obtained the privileged deployer key and uploaded a malicious contract version containing an unauthorised mint function. The security failure was therefore a compromise of software supply chain, insider access and administrative key controls that enabled malicious contract logic.
A prior PeckShield audit had documented powerful owner, minter and operator roles and classified their centralised control as a trust issue. That did not predict the exact insider and supply-chain path later described by Ankr, but it identified the consequence of privileged credentials being abused: authorised roles could mint or burn tokens and change critical configuration.
How did Ankr compensate affected users?
Ankr took a snapshot immediately after the exploit and retired aBNBc and aBNBb. It issued the replacement ankrBNB token and began airdropping ankrBNB or BNB to eligible holders and liquidity providers in December 2022. The project said its initial $15 million recovery fund was exceeded as it covered users across lending protocols, DEX pools and other integrations.
Compensation was not identical for every pool. Ankr later said 17 of 19 affected protocols received 100% coverage, while users in specified Stader BNBx and pStake stkBNB liquidity positions received 50% relief. Its February 2023 account put total compensation at approximately $30 million and announced another $3 million commitment to the BNB Chain liquid-staking ecosystem. These are Ankr's published figures; they are not an independent audit of every individual loss.
The snapshot and airdrops were incident-response measures from 2022–2023, not a current public claim campaign. Do not buy abandoned aBNBc or aBNBb tokens or connect a wallet to an unsolicited “Ankr reimbursement” page. Confirm any unresolved historical issue through Ankr's official support site.
Security changes and lessons
- Ankr said contract upgrades would require multisignature approval and timelocks rather than one developer key.
- It announced stricter access reviews, employee and contractor checks, and new monitoring and alert systems.
- An audit is a time-bounded review, not a guarantee that deployment keys, build systems or later upgrades are safe.
- Protocols should minimise privileged roles, separate duties, use hardware-backed signing, monitor upgrades and make emergency pauses transparent.
- DeFi users should consider contract-upgrade authority and liquidity concentration, not only headline APY and the existence of an audit badge.
Corrections to the original breaking-news report
- The attacker minted 60 trillion aBNBc across six transactions, not 10 trillion.
- Ankr proposed buying $5 million worth of BNB, not five million BNB.
- The later postmortem attributed the incident to a malicious former team member and a deployer-key compromise, rather than an unexplained public smart-contract bug.
- aBNBc and aBNBb were discontinued and replaced by ankrBNB.
- The compensation programme progressed beyond the initial proposal, although two protocol groups received only partial relief under Ankr's published account.
- Tornado Cash can make tracing harder, but describing funds as totally untraceable or fully laundered overstates what a mixer proves.
Original 2 December 2022 report (historical archive)
The report below is preserved substantially as published. Its breaking-news figures, present-tense claims and compensation proposal were later superseded by Ankr's incident reports.
In a shocking turn of events, the Ankr aBNBc contract was recently attacked, resulting in the creation of an additional 10 trillion aBNBc tokens. This is particularly concerning because BNB Chain had recently launched the liquid staking feature, which allowed users to earn interest by staking their BNB tokens to the liquid staking agreement and receiving aBNBc tokens in return. The attack happened in the following transaction: https://bscscan.com/address/0xf3a465c9fa6663ff50794c698f600faa4b05c777
Quick Summary:
- Ankr aBNBc contract was attacked, resulting in the creation of 10 trillion additional aBNBc tokens.
- Ankr announced they would purchase 5 million BNB worth of tokens to compensate the liquidity providers.
- Tornado Cash is being used to launder the stolen funds
- Ankr had previously received an Audit from Peckshield warning about a “trust issue of Admin Keys”, which had the potential to be used for privileged minting of aBNB tokens.
- Companies must take security warnings seriously and address any potential vulnerabilities as soon as possible to avoid catastrophic financial losses and reputational damage.
What is the Ankr Platform
Ankr is a blockchain-based cross-chain infrastructure with a DeFi platform that enables staking and dApp development, and was designed and developed with the goal of creating a decentralized, private, and secure internet. Through the Stkr protocol, users are able to stake Ethereum (ETH) in return for aETH, which represents the future gains on their deposited staking balance. With their mainnet launched in 2019, users can deploy development nodes and build dApps on the network, or deploy staking nodes and become stakers on the ANKR Web3 platform.
What happened with the exploit
The Ankr Exploiter was able to transfer 900 BNB into Tornado Cash, which caused the price of aBNBc to drop by 99.5%. In response to this security breach, Ankr announced that they would purchase 5 million BNB worth of tokens and use them to compensate the liquidity providers. Additionally, they plan to take a snapshot and reissue ankrBNB to all valid aBNBc holders before the exploit.
Tornado Cash is an Ethereum-based noncustodial privacy platform that provides users with the ability to deposit and withdraw ERC-20 tokens and ETH without revealing the source of the funds. A secret hash is generated by the protocol whenever a user deposits funds into the liquidity pools and this hash is used to prove ownership when they wish to withdraw. This ensures that the source of the funds is untraceable, providing total asset privacy. In 2020, ownership of Tornado Cash was transferred to its community, making it a fully decentralized protocol. As such, no one individual or entity has control over it, thereby ensuring that users can use the protocol in complete confidence that their privacy is secure.
This incident serves as a reminder that having an audit does not guarantee security. Ankr had previously received an Audit from Peckshield warning about the ‘trust issue of Admin Keys’, which had the potential to be used for privileged minting of aBNB tokens. Despite this warning, the team “Confirmed” the warning but failed to address the underlying issue.
As this incident demonstrates, it is essential that companies take security warnings seriously and address any potential vulnerabilities as soon as possible. Without proper security measures in place, companies risk potentially catastrophic financial losses and reputational damage. It is therefore important that companies regularly review their security protocols and remain vigilant against possible threats.
Frequently asked questions
When did the Ankr aBNBc exploit happen?
Ankr identified the attack on 1 December 2022 UTC. Much of the first reporting and response was published on 2 December, so both dates appear in contemporary coverage.
How many aBNBc tokens did the attacker mint?
Ankr's incident report says the attacker minted 60 trillion aBNBc across six transactions. The original breaking-news figure of 10 trillion was incomplete.
How much was lost in the aBNBc exploit?
Ankr initially estimated about $5 million worth of BNB was drained from liquidity pools. Broader ecosystem disruption and later compensation were larger measures than that direct-loss estimate.
What caused the Ankr exploit?
Ankr said a malicious former team member used social engineering and a supply-chain attack to compromise the deployer key. The attacker then deployed malicious contract code with an unauthorised mint function.
Was the exploit caused by a flaw in the original aBNBc contract?
Ankr described it as a compromised privileged key and malicious contract replacement, not an outsider exercising a permissionless flaw in the original deployed logic. The incident still exposed weaknesses in upgrade authority and key management.
Did Ankr compensate users?
Ankr issued replacement tokens and BNB through a snapshot-based recovery programme. It later reported full compensation for users affected through 17 of 19 protocols and 50% relief for specified Stader and pStake liquidity positions.
What happened to aBNBc and aBNBb?
Ankr discontinued both tokens after the incident and replaced them with ankrBNB. Old aBNBc and aBNBb should not be treated as current supported liquid-staking assets.
Is the Ankr compensation claim still open?
The public recovery described here used a December 2022 snapshot and staged airdrops. It is not a current open airdrop. Anyone with a historical issue should use Ankr's official support channels and avoid third-party claim links.
Did an audit prevent the aBNBc attack?
No. PeckShield had reviewed the contracts and documented privileged-role trust assumptions, but an audit does not secure employee access, software supply chains or deployer keys after the review.
What is the main security lesson from the Ankr exploit?
Critical upgrades should not depend on one privileged key. Multisignature approval, timelocks, separated duties, hardware-backed signing, access monitoring and rehearsed incident response all reduce the impact of a compromised insider or build process.
Sources
- Ankr: aBNBc token report, loss estimate and initial response
- Ankr: after-action report and root-cause account
- Ankr: December 2022 recovery milestones and snapshot
- Ankr: February 2023 compensation totals and partial-relief explanation
- Ankr: replacement of aBNBc and aBNBb with ankrBNB
- PeckShield: 2022 Ankr BNB staking contract audit and privileged-role trust issue
- BscScan: attacker address and on-chain transactions
Share
Found this useful?
Share it with someone who'd want to read it.
Related

Crypto Wallet Supply-Chain Attack: What Happened and How to Stay Safe
What crypto users need to know about the September 2025 JavaScript package compromise, including the wallet risk and practical steps to reduce exposure.

What Happens to Seized Crypto? U.S. Forfeiture Laws Explained
Frozen, seized and forfeited crypto have different legal meanings. Learn the U.S. process, how wallets are controlled and what happens to assets afterward.

Cosmos EVM Hack Explained: How Shared Code Drained Multiple Chains
Attackers used a shared Cosmos EVM flaw to drain KiiChain and TAC and force emergency halts across several networks. The code failed, but so did the warning system around it.
