Mobius Token (MBU) hack — May 2025
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | May 11, 2025 |
| Target type | Token contract |
| Loss | $2,157,126Published estimates range $2,150,000 to $2,160,000Price at time of incident |
| Method | Contract logic errorDecimal-scaling error in the unverified implementation contract behind the MBU deposit proxy on BNB Chain. A surplus 10^18 multiplier in the BNB-to-USDT-to-MBU conversion helper inflated the minted token amount by eighteen orders of magnitude, so a 0.001 BNB deposit minted roughly 9.73 quadrillion MBU. |
| Chains | BNB Chain |
| Outcome | Unresolved |
What happened
On 11 May 2025 an attacker exploited the deposit function of the Mobius Token (MBU) contract system on BNB Chain and extracted roughly $2.15-2.16 million in stablecoins.
MBU used an upgradeable proxy pointing at an unverified implementation contract. That contract converted a deposit of BNB into a USDT value, then into an MBU mint amount derived from PancakeSwap pair reserves. CertiK's analysis found a surplus 10^18 multiplier at the end of the conversion helper, which inflated the mint amount by eighteen orders of magnitude. Verichains reached the same conclusion independently, describing a helper that applied decimal scaling twice and produced an erroneous conversion factor that downstream mint operations never corrected.
The attacker deposited 0.001 BNB and received roughly 9.73 quadrillion MBU. Those tokens were sold into the project's own liquidity for 2,157,126 USDT inside a single transaction. Cyvers, which flagged the incident in real time, recorded the malicious contract being deployed at 07:31 UTC with draining beginning about two minutes later.
CertiK traced the proceeds being converted and moved through Tornado Cash in 21 batches of 100 BNB each, 2,100 BNB in total. No funds have been reported returned and no arrests have been announced.
Published figures differ slightly. Verichains and most contemporaneous reporting round the loss to $2.15 million, while CertiK cites the exact 2,157,126.18 USDT received by the attacker. Security firms writing up the incident noted that the Mobius team had not issued an official statement or post-mortem, and the implementation contract's source was never verified on BscScan.
Sources
- CertiKSecondary · retrieved 2026-08-01
- VerichainsSecondary · retrieved 2026-08-01
- The Blockchain (reporting Cyvers detection)Secondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Mobius Token (MBU) hack — May 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/mobius-tokenhttps://itokenly.com/hacks/mobius-tokenPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.