Bondly Attack: July 14th 2021 Postmortem

Letter From Harry Liu

Dear Bondly Community,

  • Our project’s interoperability added to the complexity of the investigation, as the attack occurred on the following three chains: Etherum, Binance Smart Chain and Polygon.
  • Over the course of the next 24 hours, hundreds of small transfers of 10,000, 20,000 and 200,000 $BONDLY were made to numerous wallet addresses, which we believe were owned by the Attacker. In addition to Bondly tokens, the transfers included 271,790,246 $BONDLY BSC tokens and 6,620,128 $BONDLY Polygon tokens. In our analysis, we noted that a significant portion of the fraudulently acquired tokens were sold to exchange platforms. BSCscan example.
  • Bondly executives notified the following exchanges of the compromise and recommended that they immediately stop trading $BONDLY to protect our community and investors:
  • Uniswap
  • PancakeSwap
  • MXC (MEXC)
  • BitMart
  • Gate.io
  • Bittrex