{"investigation":{"slug":"ankr","entity_name":"Ankr","trust_score":58,"severity_base":null,"score_modifier":20,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Ankr is a Web3 infrastructure and liquid staking protocol founded in 2017, providing RPC endpoints for over 75 blockchains and BNB Chain-based liquid staking products. In December 2022, a former employee executed a supply chain attack that compromised Ankr's private deployer key, enabling unlimited minting of aBNBc tokens and resulting in approximately $5 million in direct losses, with cascading secondary losses of roughly $19 million through Helio Protocol's HAY stablecoin depeg. Ankr subsequently compensated affected users, implemented multi-signature controls, and continues to operate, though questions persist over the completeness of user reimbursement.","sections":[{"content":"Ankr was founded in 2017 by Chandler Song, Ryan Fang, and Stanley Wu. The project raised approximately $18.7 million through an ICO on Binance Launchpad in March 2019, issuing the native ANKR token (ERC-20, capped at 10 billion tokens) at $0.0067 per token. Ankr operates a globally distributed network of bare-metal servers acting as nodes for over 75 blockchains, providing RPC endpoints and APIs. In 2020, Ankr launched its Stkr liquid staking protocol, which later evolved into a suite of BNB Chain-based staking derivatives including aBNBc (Ankr Reward Bearing Staked BNB) and ankrBNB. The ANKR token is used for payments, staking, and governance voting.","heading":"Background and Overview","sources":[{"url":"https://kriptomat.io/cryptocurrencies/ankr/what-is-ankr/","name":"kriptomat.io","type":"other","credibility":3},{"url":"https://www.ankr.com/","name":"ankr.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On December 1-2, 2022, Ankr suffered a critical security breach attributed to a former team member. According to Ankr's official post-mortem, the attacker conducted a supply chain attack combined with social engineering, inserting malicious code into a software update package. When a legitimate update was applied to Ankr's internal systems, the malicious code extracted the team's deployer private key from company servers. With access to the deployer key (address 0x2ffc59d32a524611bb891cab759112a51f9e33c0), the attacker deployed a new malicious version of the aBNBc token contract that added an unauthorized minting function (function selector 0x3b3a5522), bypassing all caller verification checks. The attacker minted approximately 60 trillion aBNBc tokens across six transactions and proceeded to swap them on PancakeSwap and other decentralized exchanges, extracting approximately $5 million in USDC before on-chain liquidity was exhausted. On-chain security firm PeckShield flagged the exploit at approximately 12:35 UTC on December 2, 2022. The aBNBc token price fell approximately 99.5% from roughly $303 to $1.53 within hours of the attack. The attacker (address 0xf3a465c9fa6663ff50794c698f600faa4b05c777) bridged proceeds via Celer and deBridgeGate to Ethereum and routed approximately 3,360 ETH through Tornado Cash across multiple transactions. An additional 900 BNB was sent through Tornado Cash separately. Approximately 1,000 BNB remained at an address associated with a prominent centralized exchange at the time of reporting.","heading":"December 2022 Private Key Compromise and aBNBc Exploit","sources":[{"url":"https://www.ankr.com/blog/after-action-report-our-findings-from-abnbc-token-exploit/","name":"ankr.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/ankr-confirms-exploit-asks-for-immediate-trading-halt","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://rekt.news/ankr-helio-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.merklescience.com/blog/hack-track-analysis-of-ankr-exploit","name":"merklescience.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2022/12/21/defi-protocol-ankr-says-ex-employee-caused-5m-exploit","name":"coindesk.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The collapse of aBNBc's price triggered a secondary exploit against Helio Protocol, which used aBNBc as collateral for its HAY stablecoin. Helio's price oracle was not updated following the aBNBc crash, creating an arbitrage opportunity. One attacker purchased 183,885 aBNBc tokens for approximately 10 BNB (~$2,800) and used them as collateral to borrow 16 million HAY, which was then swapped for approximately $15.5 million BUSD. A second address executed the same strategy and extracted approximately $3.5 million. HAY stablecoin depegged, reaching a low of approximately $0.20 before partially recovering. Helio subsequently repurchased and burned approximately 15 million HAY to restore the peg to near $0.99. Total losses across the Ankr primary exploit and Helio secondary exploit were approximately $24 million.","heading":"Cascading Impact: Helio Protocol and HAY Stablecoin Depeg","sources":[{"url":"https://rekt.news/ankr-helio-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/ankr-deploys-15m-to-make-whole-users-as-helio-stablecoin-recovers-after-exploit","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2022/12/03/helio-protocol-exploited-for-15m-after-ankr-exploit/","name":"cryptotimes.io","type":"other","credibility":3},{"url":"https://beincrypto.com/bnb-based-hay-destablecoin-loses-peg-ankr-exploit/","name":"beincrypto.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Ankr publicly attributed the attack to a former team member who was no longer employed at the time of the exploit. The company stated the individual inserted malicious code via a supply chain attack on internal software update packages. Ankr alerted law enforcement and stated it was 'in the process of working with law enforcement to prosecute the former team member and bring them to justice.' As of available reporting through 2023, no public confirmation of an arrest, indictment, or successful prosecution of the identified former employee has been reported. The individual was not publicly named by Ankr in official communications reviewed.","heading":"Insider Threat Attribution","sources":[{"url":"https://www.ankr.com/blog/after-action-report-our-findings-from-abnbc-token-exploit/","name":"ankr.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/ankr-says-ex-employee-caused-5m-exploit-vows-to-improve-security","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/business/2022/12/21/defi-protocol-ankr-says-ex-employee-caused-5m-exploit","name":"coindesk.com","type":"other","credibility":3},{"url":"https://blockworks.co/news/ankr-confirms-5m-crypto-hack-was-an-inside-job","name":"blockworks.co","type":"other","credibility":3}],"severity":"medium"},{"content":"Ankr announced a compensation plan for affected users, stating it would purchase $5 million in BNB to reimburse liquidity providers drained by the exploit, and airdropped ankrBNB tokens to replace affected aBNBc holdings. Ankr claimed it compensated affected users across staking solutions and protocols an aggregate amount of approximately $30 million. However, a group identifying as 'victims of the Ankr exploit' disputed the adequacy of this compensation. The group alleged that Ankr only reimbursed them 50% of BNB lost, specifically noting that users holding tokens through two affected protocols — Stader and pStake — received relief for only 50% of their value lost rather than 100%. Ankr published its own account of relief efforts and maintained its compensation stance was appropriate given the scope of cascading losses across multiple third-party protocols.","heading":"Compensation Disputes and User Reimbursement","sources":[{"url":"https://cointelegraph.com/news/ankr-exploit-victims-group-alleges-the-company-only-reimbursed-them-50","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://zycrypto.com/ankr-reveals-compensation-plan-for-users-affected-by-5-million-hack/","name":"zycrypto.com","type":"other","credibility":3},{"url":"https://www.ankr.com/blog/the-details-of-ankrs-bnb-exploit-relief-efforts-and-our-stance-on-compensation/","name":"ankr.com","type":"other","credibility":3},{"url":"https://www.coindesk.com/markets/2022/12/02/defi-protocol-ankr-exploited-for-over-5m","name":"coindesk.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the December 2022 incident, Ankr implemented several security improvements. The company moved to multi-signature authentication with timelocks for all smart contract updates, eliminating the single-point-of-failure deployer key model. Enhanced background checks were instituted for all employees, contractors, and remote workers. New monitoring and alerting systems were deployed alongside a bug bounty program. A security audit of ANKR smart contracts was conducted. In 2024, Ankr's enterprise services arm Asphere achieved SOC 2 Type 1 compliance, followed by SOC 2 Type 2 compliance in 2025. Ankr also published a public safety and risk framework blog post outlining its ongoing approach to protocol security.","heading":"Post-Exploit Security Measures","sources":[{"url":"https://www.ankr.com/blog/after-action-report-our-findings-from-abnbc-token-exploit/","name":"ankr.com","type":"other","credibility":3},{"url":"https://www.ankr.com/blog/ankr-2025-wrap-up/","name":"ankr.com","type":"other","credibility":3},{"url":"https://www.ankr.com/blog/ankr-approach-to-safety-risk-and-protecting-our-community/","name":"ankr.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/ankr-says-ex-employee-caused-5m-exploit-vows-to-improve-security","name":"cointelegraph.com","type":"other","credibility":3}],"severity":"medium"},{"content":"AVOID.NET has flagged this entity based on investigative tracking by ZachXBT, a pseudonymous on-chain investigator whose work is widely cited by Tier 2 and Tier 1 media. The specific basis for ZachXBT's flag of Ankr has not been independently verified in publicly available posts reviewed during this investigation. Given the December 2022 insider supply chain attack, the confirmed use of Tornado Cash to launder proceeds, and the unresolved questions around full user reimbursement, the flagging is consistent with the documented incident record.","heading":"ZachXBT Flagging","sources":[{"url":"https://zachxbt.mirror.xyz/","name":"zachxbt.mirror.xyz","type":"other","credibility":3},{"url":"https://medium.com/@investigationsbyzachxbt","name":"medium.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2017","event":"Ankr founded by Chandler Song, Ryan Fang, and Stanley Wu.","source":"","date_original":"2017-01-01"},{"date":"2019-03","event":"ANKR token launched via ICO on Binance Launchpad, raising approximately $18.7 million.","source":"","date_original":"2019-03-01"},{"date":"2019","event":"Ankr mainnet released.","source":"","date_original":"2019-01-01"},{"date":"2020","event":"Ankr launches Stkr liquid staking protocol, introducing aBNBc and related derivatives.","source":"","date_original":"2020-01-01"},{"date":"2022-12","event":"Former Ankr employee's malicious supply chain code activates upon a legitimate software update, exfiltrating the deployer private key.","source":"","date_original":"2022-12-01"},{"date":"2022-12-02","event":"Attacker deploys malicious aBNBc contract and mints approximately 60 trillion aBNBc tokens. PeckShield flags exploit at 12:35 UTC. Approximately $5 million extracted via PancakeSwap and bridged to Ethereum. aBNBc price crashes ~99.5%.","source":""},{"date":"2022-12-02","event":"Secondary exploit against Helio Protocol: attackers use collapsed aBNBc as collateral to drain approximately $15.5 million from Helio's HAY stablecoin pool via an unupdated price oracle. HAY depegs to $0.20.","source":""},{"date":"2022-12-02","event":"Approximately 3,360 ETH laundered through Tornado Cash; additional 900 BNB sent through Tornado Cash.","source":""},{"date":"2022-12-02","event":"Ankr issues public statement confirming exploit, requests trading halt on aBNBc, announces compensation plan.","source":""},{"date":"2022-12-21","event":"Ankr formally attributes attack to a former team member, announces law enforcement referral, and details new multi-signature security controls.","source":""},{"date":"2023","event":"Victims group publicly alleges Ankr provided only 50% reimbursement to users affected through Stader and pStake protocols.","source":"","date_original":"2023-01-01"},{"date":"2024","event":"Ankr's Asphere enterprise arm achieves SOC 2 Type 1 compliance.","source":"","date_original":"2024-01-01"},{"date":"2025","event":"Ankr's Asphere achieves SOC 2 Type 2 compliance. No public confirmation of prosecution of the former employee has been reported.","source":"","date_original":"2025-01-01"}],"sources_used":[{"url":"https://kriptomat.io/cryptocurrencies/ankr/what-is-ankr/","name":"kriptomat.io","type":"other","archive_url":"https://web.archive.org/web/20260829134645/https://kriptomat.io/cryptocurrency-prices/ankr-price/what-is/","credibility":3,"archive_timestamp":"2026-08-29T13:46:45+00:00"},{"url":"https://www.ankr.com/","name":"ankr.com","type":"other","archive_url":"http://web.archive.org/web/20260829015511/https://www.ankr.com/","credibility":3,"archive_timestamp":"2026-08-29T01:55:11+00:00"},{"url":"https://www.ankr.com/blog/after-action-report-our-findings-from-abnbc-token-exploit/","name":"ankr.com","type":"other","archive_url":"http://web.archive.org/web/20260121002552/https://www.ankr.com/blog/after-action-report-our-findings-from-abnbc-token-exploit/","credibility":3,"archive_timestamp":"2026-01-21T00:25:52+00:00"},{"url":"https://cointelegraph.com/news/ankr-confirms-exploit-asks-for-immediate-trading-halt","name":"cointelegraph.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://rekt.news/ankr-helio-rekt","name":"rekt.news","type":"other","archive_url":"http://web.archive.org/web/20260415160133/https://rekt.news/ankr-helio-rekt","credibility":3,"archive_timestamp":"2026-04-15T16:01:33+00:00"},{"url":"https://www.merklescience.com/blog/hack-track-analysis-of-ankr-exploit","name":"merklescience.com","type":"other","archive_url":"http://web.archive.org/web/20260610220420/https://www.merklescience.com/blog/hack-track-analysis-of-ankr-exploit","credibility":3,"archive_timestamp":"2026-06-10T22:04:20+00:00"},{"url":"https://www.coindesk.com/business/2022/12/21/defi-protocol-ankr-says-ex-employee-caused-5m-exploit","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20250916065220/https://www.coindesk.com/business/2022/12/21/defi-protocol-ankr-says-ex-employee-caused-5m-exploit","credibility":3,"archive_timestamp":"2025-09-16T06:52:20+00:00"},{"url":"https://cointelegraph.com/news/ankr-deploys-15m-to-make-whole-users-as-helio-stablecoin-recovers-after-exploit","name":"cointelegraph.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://www.cryptotimes.io/2022/12/03/helio-protocol-exploited-for-15m-after-ankr-exploit/","name":"cryptotimes.io","type":"other","archive_url":"https://web.archive.org/web/20260830005027/https://www.cryptotimes.io/2022/12/03/helio-protocol-exploited-for-15m-after-ankr-exploit/","credibility":3,"archive_timestamp":"2026-08-30T00:50:27+00:00"},{"url":"https://beincrypto.com/bnb-based-hay-destablecoin-loses-peg-ankr-exploit/","name":"beincrypto.com","type":"other","archive_url":"http://web.archive.org/web/20260131163041/https://beincrypto.com/bnb-based-hay-destablecoin-loses-peg-ankr-exploit/","credibility":3,"archive_timestamp":"2026-01-31T16:30:41+00:00"},{"url":"https://cointelegraph.com/news/ankr-says-ex-employee-caused-5m-exploit-vows-to-improve-security","name":"cointelegraph.com","type":"other","archive_url":"https://web.archive.org/web/20260830040821/https://cointelegraph.com/news/ankr-says-ex-employee-caused-5m-exploit-vows-to-improve-security","credibility":3,"archive_timestamp":"2026-08-30T04:08:21+00:00"},{"url":"https://blockworks.co/news/ankr-confirms-5m-crypto-hack-was-an-inside-job","name":"blockworks.co","type":"other","archive_url":"http://web.archive.org/web/20260125032144/https://blockworks.co/news/ankr-confirms-5m-crypto-hack-was-an-inside-job","credibility":3,"archive_timestamp":"2026-01-25T03:21:44+00:00"},{"url":"https://cointelegraph.com/news/ankr-exploit-victims-group-alleges-the-company-only-reimbursed-them-50","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260410233027/https://cointelegraph.com/news/ankr-exploit-victims-group-alleges-the-company-only-reimbursed-them-50","credibility":3,"archive_timestamp":"2026-04-10T23:30:27+00:00"},{"url":"https://zycrypto.com/ankr-reveals-compensation-plan-for-users-affected-by-5-million-hack/","name":"zycrypto.com","type":"other","archive_url":"https://web.archive.org/web/20260829154757/https://zycrypto.com/ankr-reveals-compensation-plan-for-users-affected-by-5-million-hack/","credibility":3,"archive_timestamp":"2026-08-29T15:47:57+00:00"},{"url":"https://www.ankr.com/blog/the-details-of-ankrs-bnb-exploit-relief-efforts-and-our-stance-on-compensation/","name":"ankr.com","type":"other","archive_url":"http://web.archive.org/web/20260208170729/https://www.ankr.com/blog/the-details-of-ankrs-bnb-exploit-relief-efforts-and-our-stance-on-compensation/","credibility":3,"archive_timestamp":"2026-02-08T17:07:29+00:00"},{"url":"https://www.coindesk.com/markets/2022/12/02/defi-protocol-ankr-exploited-for-over-5m","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20260729051155/https://www.coindesk.com/markets/2022/12/02/defi-protocol-ankr-exploited-for-over-5m","credibility":3,"archive_timestamp":"2026-07-29T05:11:55+00:00"},{"url":"https://www.ankr.com/blog/ankr-2025-wrap-up/","name":"ankr.com","type":"other","archive_url":"http://web.archive.org/web/20260415125432/https://www.ankr.com/blog/ankr-2025-wrap-up/","credibility":3,"archive_timestamp":"2026-04-15T12:54:32+00:00"},{"url":"https://www.ankr.com/blog/ankr-approach-to-safety-risk-and-protecting-our-community/","name":"ankr.com","type":"other","archive_url":"http://web.archive.org/web/20260306024420/https://www.ankr.com/blog/ankr-approach-to-safety-risk-and-protecting-our-community/","credibility":3,"archive_timestamp":"2026-03-06T02:44:20+00:00"},{"url":"https://zachxbt.mirror.xyz/","name":"zachxbt.mirror.xyz","type":"other","archive_url":"http://web.archive.org/web/20251025091919/https://zachxbt.mirror.xyz/","credibility":3,"archive_timestamp":"2025-10-25T09:19:19+00:00"},{"url":"https://medium.com/@investigationsbyzachxbt","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":true,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:46.243931+00:00","updated_at":"2026-08-30T05:14:12.091567+00:00"}}