T
iTokenly

SafeMoon hack — March 2023

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Target typeToken contract
Loss$8,900,000Price at time of incident
Recovered$7,200,000
MethodAccess control flawA contract upgrade deployed the previous day added a burn() function for bridging but left it public and unguarded, allowing any address to burn SFM held by any other address, including the SFM:BNB liquidity pair; burning the pair's SFM inflated the price of the remainder, which was then sold back into the same pool in one transaction to take out its WBNB.
ChainsBNB Chain
OutcomeSettled as bug bounty

What happened

On 28 March 2023 roughly $8.9 million of WBNB was drained from the SFM:BNB liquidity pair on BNB Chain. A SafeMoon contract upgrade deployed the day before added a burn() function intended for bridging, but the function was left public and unrestricted, so any address could burn SFM tokens held by any other address. The attacker burned the SFM sitting in the liquidity pair, which raised the price of the remaining SFM against WBNB, then sold SFM back into the pool in the same transaction at the inflated rate and removed the pool's WBNB. PeckShield published the analysis. The exploit transaction. Chief executive John Karony said the team had "located the suspected exploit, patched the vulnerability, and are engaging a chain forensics consultant to determine the precise nature and extent of the exploit", and said the incident hit the SFM:BNB pool rather than user wallets. The address that carried out the drain said it had front-run the original attacker's transaction unintentionally and offered to hand the money back. After negotiation SafeMoon said the exploiter would return 80 per cent and keep 20 per cent. On 20 April 2023 two transfers of 10,000 BNB and 11,804 BNB, together about $7.2 million, reached a SafeMoon wallet. Nobody has been identified. This exploit is separate from the federal fraud case against SafeMoon executives, in which Braden John Karony was convicted in May 2025 and sentenced in February 2026; that prosecution concerns insiders' own use of the liquidity pools and does not address the March 2023 attack.

On-chain references

Published so the figures above can be checked against the chain rather than taken from us. Victim addresses are never listed.

Transactions

  • 0x48e52a12cb297354a2a1c54cbc897cf3772328e7e71f51c9889bb8c5e533a934

Sources

  1. CoinDeskSecondary · retrieved 2026-08-01
  2. BleepingComputerSecondary · retrieved 2026-08-01
  3. CryptoSlateSecondary · retrieved 2026-08-01
  4. IRS Criminal InvestigationPrimary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "SafeMoon hack — March 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/safemoon
https://itokenly.com/hacks/safemoon

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.