An attacker attempted to dump 1,009,381
$FB tokens (~$461k) on Ethereum using MetaMask’s built-in Swap feature. The swap route went through KyberSwap Aggregator, but in return, the attacker received only $0.14 worth of
$ETH. The tokens still remain in the contract.
(Fenerbahçe Token
$FB is an ERC-20 fan/utility token issued by
@Fenerbahce Sports Club, one of Turkey’s biggest clubs, with 13.8M followers on Twitter.)
What actually happened?
* Liquidity for
$FB on DeFi was low.
* Only a tiny dust amount sold: 0.0563 FB > 0.000030149 ETH ($0.14)
* The rest of the
$FB did not sell in this tx and ended up at Kyber’s MetaAggregationRouterV2 contract.
Why this matters?
* That router contract is
etherscan.io/address/0x6131b…
* It implements a rescueFunds(token, amount) owner-only function.
* This means the contract owner can move out tokens that are stuck on the contract.
Call to action !
* Request coordination between
@BtcTurkKripto ,
@fbtokenofficial and
@KyberNetwork to recover and secure the stuck tokens.
* Tokens can be returned to a designated treasury or custodian after verification.
* Attacker address:
snowscan.xyz/address/0xa041f…
* Tx that shows only dust being sold:
etherscan.io/tx/0x9fefc12e3c…
TL;DR
* The attacker tried to dump $461k worth of
$FB but the tokens stuck in the contract.
* Kyber should return these tokens.
Update: BtcTurk (
@btcturk) was hacked for more than $48M!
The hacker is swapping the stolen assets for
$ETH.
Address:
0x0fe41fe8786329fb6bd8f2baa73aa55e770f0951
0xa041feb3a8297c5689fee180083164a061a17fd6
0x7D91D1ebeBA91257733a523409125aEdac5d8b6E
x.com/lookonchain/status/195…