Qubit Finance hack — January 2022
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | January 28, 2022 |
| Target type | Lending protocol |
| Loss | $80,000,000Price at time of incident |
| Method | Contract logic errordeprecated QBridge deposit() minted bridged ETH with no deposit because the zero token address made safeTransferFrom succeed |
| Chains | BNB Chain, Ethereum |
| Audited beforehand | Theori (QBridge, QBridgeHandler, QBridgeDelegator, QBridgeToken and the relayer, audited 1-13 December 2021; Qubit stated the vulnerable legacy deposit() path was not in the audit's coverage) |
| Attributed to | North Korea-linked actors, per Chainalysis assessmentSuspected |
| Outcome | Unresolved |
What happened
Qubit Finance, a lending protocol on BNB Chain built by the Korean team behind Mound, lost about $80 million through QBridge, its Ethereum-to-BNB Chain bridge. Starting at 21:34 UTC on 27 January 2022 the attacker repeatedly called QBridge's legacy deposit() function on Ethereum with no ETH attached and crafted calldata. Because the token address configured for native ETH was the zero address, the handler's safeTransferFrom call to an address with no code returned successfully and all three validation checks passed, so the bridge emitted deposit events for ETH that had never been sent.
CertiK's analysis found the attacker minted 77,162 qXETH on BNB Chain from those fake deposits and borrowed against it: 15,688 wETH, 767 BTC-B, roughly $9.5 million in stablecoins and about $5 million in CAKE, BUNNY and MDX. PeckShield, cited by CoinDesk, measured the haul at 206,809 BNB equivalent, over $80 million.
Qubit published two incident reports. The second gives the development timeline: Theori audited the bridge contracts between 1 and 13 December 2021, a depositETH function was added on 13 December for direct native-ETH deposits, and the older deposit function was left in the contract. Qubit wrote that the flaw "was not in the coverage of the audit performed by Theori" and that the zero-address configuration "was not intentionally set to a malicious value." The team disabled supply, redeem, borrow, repay and bridge functions and offered its maximum bug bounty for the return of the funds. Nothing was returned. In May 2023 Chainalysis said the theft was likely the work of North Korea-linked hackers.
Law enforcement
South Korea's Transnational Crime Information Center and National Intelligence Service traced the funds in partnership with Chainalysis. No arrests, charges or sanctions have been reported.
Sources
- Qubit FinancePrimary · retrieved 2026-08-01
- Qubit FinancePrimary · retrieved 2026-08-01
- CertiKSecondary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- ChainalysisSecondary · retrieved 2026-08-01
Official post-mortem: https://medium.com/@QubitFin/protocol-exploit-report-305c34540fa3
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Qubit Finance hack — January 2022", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/qubit-financehttps://itokenly.com/hacks/qubit-financePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.