T
iTokenly

Qubit Finance hack — January 2022

Verified — 5 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedJanuary 28, 2022
Target typeLending protocol
Loss$80,000,000Price at time of incident
MethodContract logic errordeprecated QBridge deposit() minted bridged ETH with no deposit because the zero token address made safeTransferFrom succeed
ChainsBNB Chain, Ethereum
Audited beforehandTheori (QBridge, QBridgeHandler, QBridgeDelegator, QBridgeToken and the relayer, audited 1-13 December 2021; Qubit stated the vulnerable legacy deposit() path was not in the audit's coverage)
Attributed toNorth Korea-linked actors, per Chainalysis assessmentSuspected
OutcomeUnresolved

What happened

Qubit Finance, a lending protocol on BNB Chain built by the Korean team behind Mound, lost about $80 million through QBridge, its Ethereum-to-BNB Chain bridge. Starting at 21:34 UTC on 27 January 2022 the attacker repeatedly called QBridge's legacy deposit() function on Ethereum with no ETH attached and crafted calldata. Because the token address configured for native ETH was the zero address, the handler's safeTransferFrom call to an address with no code returned successfully and all three validation checks passed, so the bridge emitted deposit events for ETH that had never been sent.

CertiK's analysis found the attacker minted 77,162 qXETH on BNB Chain from those fake deposits and borrowed against it: 15,688 wETH, 767 BTC-B, roughly $9.5 million in stablecoins and about $5 million in CAKE, BUNNY and MDX. PeckShield, cited by CoinDesk, measured the haul at 206,809 BNB equivalent, over $80 million.

Qubit published two incident reports. The second gives the development timeline: Theori audited the bridge contracts between 1 and 13 December 2021, a depositETH function was added on 13 December for direct native-ETH deposits, and the older deposit function was left in the contract. Qubit wrote that the flaw "was not in the coverage of the audit performed by Theori" and that the zero-address configuration "was not intentionally set to a malicious value." The team disabled supply, redeem, borrow, repay and bridge functions and offered its maximum bug bounty for the return of the funds. Nothing was returned. In May 2023 Chainalysis said the theft was likely the work of North Korea-linked hackers.

Law enforcement

South Korea's Transnational Crime Information Center and National Intelligence Service traced the funds in partnership with Chainalysis. No arrests, charges or sanctions have been reported.

Sources

  1. Qubit FinancePrimary · retrieved 2026-08-01
  2. Qubit FinancePrimary · retrieved 2026-08-01
  3. CertiKSecondary · retrieved 2026-08-01
  4. CoinDeskSecondary · retrieved 2026-08-01
  5. ChainalysisSecondary · retrieved 2026-08-01

Official post-mortem: https://medium.com/@QubitFin/protocol-exploit-report-305c34540fa3

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Qubit Finance hack — January 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/qubit-finance
https://itokenly.com/hacks/qubit-finance

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.