{"id":57717,"date":"2022-02-14T18:26:03","date_gmt":"2022-02-14T16:26:03","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=57717"},"modified":"2025-09-04T13:07:36","modified_gmt":"2025-09-04T10:07:36","slug":"defi-project-titano-finance-on-bsc-lost-1-9-million-in-a-hack","status":"publish","type":"post","link":"https:\/\/u1f987.com\/en\/defi-project-titano-finance-on-bsc-lost-1-9-million-in-a-hack\/","title":{"rendered":"DeFi project Titano Finance on BSC lost $1.9 million in a hack"},"content":{"rendered":"<p>On February 14, PeckShield researchers detected an unauthorised withdrawal of 4,828 BNB (roughly $1.9 million) from the Titano Finance DeFi protocol on the Binance Smart Chain (BSC).<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh4.googleusercontent.com\/1eTSnl4ABT_DKMKuh8r0QwChV5DWnKOuxptXywhHkc4WB07ld1yE3NDK6onXqIPv52axKoX2df8L6gwdiJdReJVVwKSPiex1QM_8YhIaqn4l3XtmG51vX7uhyxcB-Niw_1RTIrIR\" alt=\"DeFi project Titano Finance on BSC loses $1.9 million in a hack\"\/><figcaption>Screenshot of PeckShield&#8217;s initial tweet, later deleted. Data: Twitter.<\/figcaption><\/figure>\n<p>In the face of the project&#8217;s silence, PeckShield experts, as well as some other <a href=\"https:\/\/twitter.com\/Stephenjames023\/status\/1493166173353037828\">\u043a\u043e\u043c\u043c\u0435\u043d\u0442\u0430\u0442\u043e\u0440\u044b<\/a> suspected the deployment of a <span data-descr=\"a rugpull, a scheme where developers abandon a project and disappear with users' money\" class=\"old_tooltip\">rugpull<\/span> scheme.<\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"en\">\n<p lang=\"en\" dir=\"ltr\"><a href=\"https:\/\/twitter.com\/hashtag\/rugpulls?src=hash&#038;ref_src=twsrc%5Etfw\">#rugpulls<\/a> PeckShield has detected <a href=\"https:\/\/twitter.com\/TitanoFinance?ref_src=twsrc%5Etfw\">@TitanoFinance<\/a> is rugged: the owner sets the PrizeStrategy contract, which then drains about 4,828 BNB (~$1.9m)! The rugged funds were initially held in this wallet 0xad9217e427ed9df8a89e582601a8614fd4f74563 and then split into 24 addresses. <a href=\"https:\/\/t.co\/vrGbLLspGo\">pic.twitter.com\/vrGbLLspGo<\/a><\/p>\n<p>\u2014 PeckShieldAlert (@PeckShieldAlert) <a href=\"https:\/\/twitter.com\/PeckShieldAlert\/status\/1493139576554078210?ref_src=twsrc%5Etfw\">February 14, 2022<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>However most users did not share their conclusions. They noted that all Titano Finance smart contracts are still functioning. The compromised service was Titano PLAY for staking with lottery-like features \u2014 weekly among its users a prize pool is awarded, depending on the number of participants.<\/p>\n<p>Minutes after the initial PeckShield report, Titano Finance representatives confirmed the PLAY contract was hacked.<\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"en\">\n<p lang=\"en\" dir=\"ltr\">Hello Titans,<\/p>\n<p>Titano PLAY was hacked today. Titano, DID NOT mint any tokens. The PLAY contract was compromised, by a malicious hacker who created more Titano Tickets.<\/p>\n<p>Anyone involved in Titano PLAY will have their tokens fully returned.<br \/> <a href=\"https:\/\/t.co\/sfrdi0ZcOq\">https:\/\/t.co\/sfrdi0ZcOq<\/a><\/p>\n<p>\u2014 Titano (@TitanoFinance) <a href=\"https:\/\/twitter.com\/TitanoFinance\/status\/1493191421393879045?ref_src=twsrc%5Etfw\">February 14, 2022<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>They called the incident disconcerting, as the protocol&#8217;s code had passed &#8216;all security checks&#8217;. According to the pinned tweet, the audit in November 2021 was conducted by Certik.<\/p>\n<p>The team suspended the PLAY service indefinitely pending remediation of all vulnerabilities. The project promised full restitution of lost funds to affected users.<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u00abFirst, we know who you are and where you are, and we will relentlessly pursue. You have 24 hours to return the stolen funds without penalties. If this does not happen, the deal is off\u00bb.<\/p>\n<\/blockquote>\n<p>The project cited the broad community, which numbers 42,000 users, and support for the entire DeFi sector.<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u00abDo the right thing and return the money, otherwise you will never sleep easy\u00bb, \u2014 said the Titano Finance team.<\/p>\n<\/blockquote>\n<p>The protocol&#8217;s native TITANO token tumbled from $0.165 to $0.033 within an hour \u2014 roughly an 80% drop. At the time of writing, the asset had retraced much of the fall and was trading around $0.12.\u00a0\u00a0<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh3.googleusercontent.com\/O5gsojd7dyAL7yJSyzuZpRtkS5i0QhNzrt2iWuHX0tFubKPsL4ESx8Nnw-UTwrnJSMFQS5W-zKsU_Gzgp2cC_oyD42Bo4bY3M1zsyDkvx9adC1gCq1HpNoIGJ7c_PHJDoe3oCF94\" alt=\"DeFi project Titano Finance on BSC loses $1.9 million in a hack\"\/><figcaption>Data: <a href=\"https:\/\/dexscreener.com\/bsc\/0x44f382cec44c33067cb12fcfc08457eb6734be02\">DEX Screener<\/a>.<\/figcaption><\/figure>\n<p>In January, hackers drained <a href=\"https:\/\/u1f987.com\/en\/news\/hackers-drain-80-million-from-defi-platform-qubit-finance-pool\">digital assets worth about $80 million<\/a> from the Qubit Finance lending platform on BSC.<\/p>\n<p>Following the incident, the development team behind the DeFi protocols Bunny Finance <a href=\"https:\/\/u1f987.com\/en\/news\/defi-platform-qubit-finance-to-come-under-dao-governance-after-80-million-loss\">announced the transfer of governance<\/a> of the DAO projects <a href=\"https:\/\/u1f987.com\/en\/news\/what-is-a-dao-decentralised-autonomous-organisation\">DAO<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On February 14, PeckShield researchers detected an unauthorized withdrawal of 4,828 BNB (roughly $1.9 million) from the Titano Finance DeFi protocol on the Binance Smart Chain (BSC).<\/p>\n","protected":false},"author":1,"featured_media":57718,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1154,1093],"class_list":["post-57717","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-crimes","tag-defi"],"aioseo_notices":[],"amp_enabled":true,"views":"19","promo_type":"1","layout_type":"1","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/57717","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/comments?post=57717"}],"version-history":[{"count":1,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/57717\/revisions"}],"predecessor-version":[{"id":57719,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/57717\/revisions\/57719"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media\/57718"}],"wp:attachment":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media?parent=57717"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/categories?post=57717"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/tags?post=57717"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}