BetterBank hack — August 2025
Incident facts
| Date of incident | (approximate) |
|---|---|
| Publicly disclosed | August 27, 2025 |
| Target type | Decentralised exchange |
| Loss | $5,000,000Published estimates range $4,100,000 to $5,000,000Price at time of incident |
| Recovered | $2,700,000 |
| Method | Contract logic errorUnbounded reward minting. The reward-tracking swap functions in FavorRouterWrapper.sol (swapExactTokensForFavorAndTrackBonus and swapETHForFavorAndTrackBonus) minted ESTEEM bonus tokens whenever a swap produced FAVOR, but validated only that FAVOR sat at one end of the swap path and never checked that the swap had gone through an authorised liquidity pair. Swaps routed through attacker-created fake pairs therefore minted ESTEEM without limit; the ESTEEM was redeemed back into FAVOR and sold into the protocol's real pools. |
| Chains | Other |
| Audited beforehand | Zokyo (July 2025) |
| Outcome | Partially recovered |
What happened
BetterBank, a decentralised finance protocol on PulseChain built around a FAVOR token and an ESTEEM reward token, was drained across 26 and 27 August 2025.
Analyses by Kaspersky's Securelist, QuillAudits and Olympix agree on the mechanism. The protocol's router wrapper minted ESTEEM bonus tokens whenever a swap produced FAVOR, but the reward functions in FavorRouterWrapper.sol checked only that FAVOR was an endpoint of the swap path, not that the swap had passed through an authorised liquidity pair. The attacker created fake pairs holding a worthless token they controlled alongside FAVOR, swapped through them repeatedly and minted ESTEEM without limit. The ESTEEM was converted back into FAVOR and sold into the protocol's genuine pools, removing roughly 891 million pDAI, 9.05 billion PLSX and 7.40 billion WPLS.
Published figures put the initial drain at about $5 million at the time. After on-chain negotiation the attacker returned 550 million pDAI, valued at around $2.7 million, and the net amount they kept is reported as roughly $1.4 million. Those figures do not reconcile arithmetically and no full accounting has been published, so the loss is recorded here with a lower bound derived from the returned plus retained amounts.
BetterBank froze trading, drained the remaining FAVOR pools and offered a 20% bounty for information identifying the attacker. The protocol had been audited by Zokyo in July 2025. Securelist reports that the audit flagged this exact issue, that BetterBank downgraded it from critical to informational and did not apply the patch the auditor supplied; the two have since publicly disputed responsibility. The attacker has not been identified.
Sources
- Kaspersky SecurelistSecondary · retrieved 2026-08-01
- QuillAuditsSecondary · retrieved 2026-08-01
- OlympixSecondary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "BetterBank hack — August 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/betterbankhttps://itokenly.com/hacks/betterbankPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.