GYM Network hack — June 2022
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | June 8, 2022 |
| Target type | Other |
| Loss | $716,000Published estimates range $716,000 to $2,100,000Price at time of incident |
| Method | Access control flawAn externally callable depositFromOtherContract() function in the GymSinglePool contract had no caller restriction and credited a deposit balance without ever transferring tokens in; the attacker registered phantom deposits and withdrew against them. |
| Chains | BNB Chain |
| Audited beforehand | CertiK, PeckShield (exploited function added after CertiK's audit and outside its scope) |
| Outcome | Unresolved |
What happened
On 8 June 2022 an attacker drained the GymSinglePool contract of GYM Network, a yield-farming platform on BNB Chain. Two days earlier the team had deployed a new function, depositFromOtherContract(), as part of a claim-and-reinvest feature. SolidityScan found the function was declared external with no validation of the caller, so anybody could invoke it. CertiK's analysis found that the underlying _autoDeposit path contained no transfer function to move a user's deposit into the contract, so a deposit record was created without any funds arriving; ChainZoom, examining the same code, reported that the function executed only a self-approval, token.approve(address(this), _depositAmount), instead of a transfer. The attacker deployed a contract that repeatedly called it to register deposits of 8,000,000 GYMNET, immediately withdrew the phantom balances, and sold the resulting GYMNET for BNB.
Published figures differ substantially. CertiK traced the attack transactions on chain and concluded the attacker obtained 2,475.91 WBNB, about $716,000 at the time. PeckShield's figure, carried by contemporaneous news coverage and repeated by SolidityScan, was about $2.1 million, or roughly 7,500 BNB. ChainZoom described the attacker converting about 7.2 million GYMNET into roughly 3,300 BNB. This registry records CertiK's on-chain traced figure as the point estimate and the $2.1 million figure as the upper bound.
Reported price impact also differs by source: ChainZoom recorded GYMNET falling from about $0.2 to $0.026, roughly 87 percent, before recovering to about $0.08, while cryptonews.net reported a drop of over 50 percent on a different price series.
SolidityScan reported that the attacker moved about 2,000 BNB through Tornado Cash; CertiK likewise recorded the use of Tornado Cash without quantifying it. GYM Network informed its community of the incident and, per CertiK, remediated the flaw by adding an onlyBank modifier restricting the function to authorised callers. No completed compensation programme has been documented. CertiK stated the exploited contract had been deployed only two days before the attack and so was not part of the audit it had already performed; cryptonews.net reported that GYM Network had been audited by both PeckShield and CertiK.
Sources
- CertiKSecondary · retrieved 2026-08-01
- SolidityScanSecondary · retrieved 2026-08-01
- CryptoNewsSecondary · retrieved 2026-08-01
- ChainZoom SecuritySecondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "GYM Network hack — June 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/gym-networkhttps://itokenly.com/hacks/gym-networkPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.