The investigation revealed that the hacker received super-profitable staking rewards and withdrew them to the market.

Crypto project GANA Payment lost over $3,1 million as a result of a hacker attack.

21.11.2025 - 10:20

277

3 min

Blockchain security researcher ZachXBT reported that the GANA Payment crypto project on BNB Smart Chain was hit by a serious attack. The damage exceeded $3,1 million. The hacker withdrew most of the funds through Tornado Cash on the BSC and Ethereum networks, with about $1 million in ETH still untouched.

Source: Telegram

How the attack unfolded

According to ZachXBT, the attacker collected the stolen assets at the address 0x2e85c38 and then sent 1140 BNB (about $1,04 million) to Tornado Cash on BSC. Later, he transferred part of the funds to the Ethereum network and ran another 346,8 ETH (about $1,05 million) through the mixer.

HashDit quickly found the cause of the hack: the hacker changed the owner of the GANA smart contract and gained full access to the staking mechanism. This allowed him to control reward accruals and trigger staking cancellation functions, receiving far more tokens than the system intended.

Source: X.com

The attacker brought additional tokens to the market, exchanged them for more liquid assets, and then sent the funds through Tornado Cash. HashDit issued a warning and recommended temporarily refraining from trading GANA tokens until official clarification from the project team.

Other incidents on the BSC network

This hack was yet another event in the Binance Smart Chain ecosystem. Despite overall improvements, attacks are still happening. According to a report by BNB Chain and Hacken, losses on the network have decreased by 70%, from $161 million in 2023 to $47 million in 2024. However, individual attacks continue to test the network’s resilience.

Previous incidents have been recorded on the network:

  • in September, a Venus Protocol user lost $27 million by signing a malicious transaction (the protocol’s smart contracts were not affected);
  • in February, the meme platform Four.Meme lost $183 000 due to a probable sandwich attack and the volatility of the test token.

In October, hackers broke into the BNB Chain account on X and used it to publish phishing links disguised as legitimate services and BSC token distributions.

Subscribe to Getblock Magazine and stay up to date with the latest news from the world of cryptocurrencies and the digital economy