GriffinAI hack — September 2025
Incident facts
| Date of incident | (approximate) |
|---|---|
| Publicly disclosed | September 25, 2025 |
| Target type | Token contract |
| Loss | $3,000,000Published estimates range $2,500,000 to $4,000,000Price at time of incident |
| Method | Private key compromiseGAIN was a LayerZero omnichain token. An admin externally owned account with owner privileges over the GAIN contract was compromised and used to set the LayerZero peer for GAIN's endpoint to an attacker-deployed contract on Ethereum, displacing the legitimate counterpart. Because the BNB Chain side accepted mint instructions from whichever peer was configured, a message from the substituted contract minted 5 billion GAIN, five times the stated supply cap, which was then sold into liquidity. The peer-setting operation itself was owner-privileged and functioned as designed; the failure was control of the key, not a missing check in the contract. |
| Chains | Ethereum, BNB Chain |
| Outcome | Project relaunched |
What happened
GriffinAI's GAIN token was exploited within about a day of its launch in late September 2025. Most reporting dates the exploit to 25 September 2025; the token launched on 24 September and some listings use that date instead.
GAIN was deployed as a LayerZero omnichain token. An administrative externally owned account holding owner privileges over the GAIN contract was compromised, and that access was used to set the token's LayerZero peer to a contract the attacker had deployed on Ethereum, displacing the legitimate counterpart. Because the BNB Chain side accepted mint instructions from whichever peer was configured, a message from the substituted Ethereum contract minted 5 billion GAIN on BNB Chain, five times the project's stated 1 billion supply cap. The attacker sold roughly 147.5 million of those tokens into PancakeSwap and over the counter within about an hour, realising around 2,956 BNB, and routed the proceeds through deBridge and into Tornado Cash. Accounts of the price collapse differ: The Crypto Times reports an 84 percent fall from about $0.16 to about $0.017, while crypto.news reports a drop of roughly 90 percent from about $0.25 to about $0.0273.
The amount is reported inconsistently. The on-chain BNB figure works out near $3 million, crypto.news cited a $3 to $4 million range, and GriffinAI later sized its own buyback fund at $2.5 million, describing it as equivalent to what the attacker extracted. CertiK described the forged peer, and GoPlus noted the same technique had been used against Yala shortly before. QuillAudits traced the root cause to the compromise of an admin externally owned account, and Verichains described the owner of the GAIN contract on BNB Chain setting the peer to the malicious Ethereum contract. Setting a peer is an owner-privileged action, so the failure was control of the key rather than a flaw in the contract logic; no party has been formally identified and no source establishes whether the key was taken from outside or misused from within. Chief executive Oliver Feldmeier said the fake LayerZero peer allowed abnormal minting and dumping, and GriffinAI said the Ethereum version of GAIN remained unaffected and continued to operate normally. GriffinAI pulled its own BNB Chain liquidity, asked exchanges to halt trading, and relaunched the token on 6 October 2025 with a one-to-one swap based on a snapshot taken at the moment the unauthorised minting began, vesting for post-incident buyers, and the buyback fund.
Sources
- crypto.newsSecondary · retrieved 2026-08-01
- The Crypto TimesSecondary · retrieved 2026-08-01
- The Crypto TimesSecondary · retrieved 2026-08-01
- CryptoFrontNews (post on Binance Square)Secondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "GriffinAI hack — September 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/griffinaihttps://itokenly.com/hacks/griffinaiPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.