{"investigation":{"slug":"launchzone","entity_name":"LaunchZone","trust_score":18,"severity_base":null,"score_modifier":0,"confidence":0.78,"status":"published","content_type":"investigation","summary":"LaunchZone (LZ) was a Binance Smart Chain-based DeFi launchpad and IDO platform originally launched as BSCex in December 2020, later rebranded in March 2021. On February 27, 2023, the protocol suffered a critical smart contract exploit in its Bscex SwapX contract, resulting in approximately $700,000 drained from its liquidity pool and a total of nearly $7.8 million in cumulative losses as additional vulnerable contracts were identified. The platform ceased operations on March 26, 2023, with over 75,000 user wallets remaining exposed weeks after the initial attack. ZachXBT has flagged this entity as a risk.","sections":[{"content":"LaunchZone was founded as BSCex (also written BSCEX) in December 2020, positioning itself as the first decentralized, non-custodial cryptocurrency exchange ecosystem on Binance Smart Chain (BSC). The project rebranded to LaunchZone in March 2021 to reflect a broader focus on launchpad services for early-stage crypto projects. The ecosystem comprised LZ Swap, LZ Pool, LZ Wallet, and a token launchpad powered by the native $LZ governance token (BEP-20, total supply 50,000,000). The rebrand included acquisitions of The Sowing Network, BSC Army, and ezDeFi, with token migrations from BSCX to LZ and from zSeed/ZDcash/BARMY to LZP. By its peak, LaunchZone claimed an all-time high trading volume exceeding $1 billion and conducted 25 IDOs raising approximately $5.61 million in aggregate. The platform expanded to the IoTeX network through a partnership announced in 2021. LaunchZone's IDO participants included projects such as StepHeroNFT, Pebble GO ($PBG), mimo ($MIMO), and HealthBlocks ($HEALTH).","heading":"Platform Overview and History","sources":[{"url":"https://iotex.io/blog/launchzone-partnership-ido-launchpad/","name":"iotex.io","type":"other","credibility":3},{"url":"https://cryptorank.io/fundraising-platforms/launch-zone","name":"cryptorank.io","type":"other","credibility":3},{"url":"https://www.bsc.news/post/launchzone-to-host-ido-for-play-to-earn-gamefi-project-stepheronft","name":"bsc.news","type":"other","credibility":3}],"severity":"medium"},{"content":"On February 27, 2023, at approximately 7:32 a.m. UTC, an attacker drained approximately $700,000 from LaunchZone's liquidity pool on Binance Smart Chain. The exploit targeted the Bscex SwapX smart contract, an exchange instrument embedded in the LaunchZone ecosystem. The root cause was identified as an insufficient access control vulnerability in the implementation contract: the attacker exploited excessive user permission grants, allowing the malicious contract to loop through approved user addresses and force trades on their behalf, effectively manipulating token prices and draining pool liquidity. The attacker deployed a contract with unverified source code (malicious contract address: 0x1c2b102f22c08694eee5b1f45e7973b6eaca3e92), executed the drain via PancakeSwap, then called a self-destruct function transferring stolen assets to the exploiter address (0x7d192fa3a48c307100c3e663050291fff786aa1f). Stolen funds were subsequently routed through FixedFloat and Tornado Cash to obscure their trail. The LZ/BUSD trading pair showed a 7,000% spike in 24-hour trading volume at the time of attack, serving as an on-chain indicator of the exploit. The same attacker, labeled the 'DND Exploiter,' simultaneously struck DungeonSwap ($DND) for approximately $728,000 and also exploited the $HFI (HecoFi) protocol for an additional $18,940, suggesting a coordinated multi-protocol attack.","heading":"February 2023 Smart Contract Exploit","sources":[{"url":"https://smartcontractshacking.com/hacks/launchzone-hack-2023","name":"smartcontractshacking.com","type":"other","credibility":3},{"url":"https://medium.com/neptune-mutual/dungeon-swap-and-launch-zone-exploit-d9cb9c8b026","name":"medium.com","type":"other","credibility":3},{"url":"https://beincrypto.com/bnb-chain-protocol-launchzone-exploited-700k/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://u.today/75000-bsc-addresses-still-at-risk-after-launchzone-hack","name":"u.today","type":"other","credibility":3}],"severity":"medium"},{"content":"Initial reports on February 27, 2023 cited approximately $700,000 drained. However, as security researchers continued analyzing the vulnerable contracts, total cumulative losses reached approximately $7,792,137 across all affected contracts and time periods. The four vulnerable LaunchZone smart contracts had been deployed between January and October 2021, meaning user wallets that had interacted with the platform over a two-year period remained exposed. As of March 27, 2023 — five weeks after the initial exploit disclosure — 75,564 BSC addresses had not revoked their token approvals on the compromised contracts, leaving them vulnerable to further exploitation. Only 7,860 addresses had taken the necessary steps to revoke approvals. The $LZ token price collapsed 83–86% within hours of the attack disclosure, falling from approximately $0.15 to $0.000086. Biswap, a BNB Chain decentralized exchange, delisted the LZ token within five hours of the hack announcement.","heading":"Scale of Losses and User Exposure","sources":[{"url":"https://u.today/75000-bsc-addresses-still-at-risk-after-launchzone-hack","name":"u.today","type":"other","credibility":3},{"url":"https://cryptonews.net/news/security/20718794/","name":"cryptonews.net","type":"other","credibility":3},{"url":"https://beincrypto.com/bnb-chain-protocol-launchzone-exploited-700k/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://smartcontractshacking.com/hacks/launchzone-hack-2023","name":"smartcontractshacking.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the February 27, 2023 attack, LaunchZone immediately paused trading and transfers of its native LZ token and restricted replies on its official Twitter announcement. The team's initial communication came through the project's Telegram group, which warned users: '$LZ is being hacked from DND exploiter. The team is handling the situation, please don't buy the token at this stage.' The project did not make any warnings or announcements to its approximately 275,000 Twitter followers at the time of the attack. On March 7, 2023, the team announced a compensation program: affected users would receive $iRD tokens subject to a 15-month vesting period, with $iRD convertible to $RD tokens for transactions and stakeable to earn $USDC rewards. The team also announced plans to relocate LZ token liquidity to Arbitrum and pledged to refund investors who purchased tokens after the attack without subsequently selling them. LaunchZone's website (lz.finance) ceased operations on March 26, 2023, approximately four weeks after the exploit. The protocol has not resumed normal operations as of the date of this investigation.","heading":"Team Response, Compensation Plan, and Protocol Shutdown","sources":[{"url":"https://protos.com/defi-project-launchzone-claims-to-be-latest-victim-of-bnb-chain-exploits/","name":"protos.com","type":"other","credibility":3},{"url":"https://www.bitdegree.org/crypto/news/defi-protocol-launchzone-lost-around-300-000-in-a-liquidity-pool-exploit","name":"bitdegree.org","type":"other","credibility":3},{"url":"https://cryptonews.net/news/security/20718794/","name":"cryptonews.net","type":"other","credibility":3},{"url":"https://u.today/75000-bsc-addresses-still-at-risk-after-launchzone-hack","name":"u.today","type":"other","credibility":3}],"severity":"medium"},{"content":"While LaunchZone characterized the February 2023 incident as an external exploit perpetrated by the 'DND Exploiter,' a segment of the community alleged the incident may have been a rug pull rather than a genuine third-party attack. These allegations were fueled by several factors: the team's failure to alert its 275,000 Twitter followers at the time of the exploit, the immediate and severe token price collapse of over 80%, the lack of a proactive security audit program despite operating for over two years, and the rapid website shutdown following the hack. Community members on Twitter and other platforms expressed scepticism about the exploit narrative. Neptune Mutual's independent technical analysis confirmed insufficient access controls in the implementation contract, which is consistent with either negligent development practices or deliberate backdoor inclusion — the latter claim remaining unverified and at a low confidence tier. No law enforcement action or formal investigation by blockchain security firms has publicly attributed the attack to internal actors. These allegations should therefore be treated as unverified community claims.","heading":"Rug Pull Allegations and Community Suspicions","sources":[{"url":"https://protos.com/defi-project-launchzone-claims-to-be-latest-victim-of-bnb-chain-exploits/","name":"protos.com","type":"other","credibility":3},{"url":"https://medium.com/neptune-mutual/dungeon-swap-and-launch-zone-exploit-d9cb9c8b026","name":"medium.com","type":"other","credibility":3},{"url":"https://web3isgoinggreat.com/single/two-bnb-based-projects-attacked","name":"web3isgoinggreat.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The LaunchZone exploit yielded several notable on-chain indicators that serve as post-mortem risk signals. The attacker address (0x7d192fa3a48c307100c3e663050291fff786aa1f) was linked to simultaneous attacks on multiple BSC protocols, indicating a sophisticated, coordinated threat actor rather than an opportunistic exploit. The attacker routed stolen funds through FixedFloat and Tornado Cash, standard laundering paths for crypto theft proceeds. The malicious contract (0x1c2b102f22c08694eee5b1f45e7973b6eaca3e92) used an unverified source code and a self-destruct mechanism to destroy evidence on-chain. The LaunchZone LZ token contract remains on BSCScan (0x3b78458981eb7260d1f781cb8be2caac7027dbe2) and is effectively defunct. Vulnerable contracts deployed as early as January 2021 suggest the access control flaw existed undetected — or unaddressed — for approximately two years prior to exploitation. No independent smart contract audit from a recognized firm (e.g., CertiK, PeckShield, Quantstamp) has been publicly associated with the compromised contracts.","heading":"On-Chain Risk Indicators","sources":[{"url":"https://smartcontractshacking.com/hacks/launchzone-hack-2023","name":"smartcontractshacking.com","type":"other","credibility":3},{"url":"https://medium.com/neptune-mutual/dungeon-swap-and-launch-zone-exploit-d9cb9c8b026","name":"medium.com","type":"other","credibility":3},{"url":"https://bscscan.com/token/0x3b78458981eb7260d1f781cb8be2caac7027dbe2","name":"bscscan.com","type":"other","credibility":3},{"url":"https://cryptonews.net/news/security/20718794/","name":"cryptonews.net","type":"other","credibility":3}],"severity":"medium"},{"content":"LaunchZone has been flagged by ZachXBT, the pseudonymous blockchain investigator known for on-chain investigations of crypto scams, exploits, and fraud. ZachXBT's public track record includes identifying rug pulls, insider exploits, and deceptive project structures across BSC and other chains. The specific basis of the ZachXBT flag on LaunchZone has not been independently verified through a public, archived post at the time of this investigation's compilation. The flag is treated here as a credible risk signal given ZachXBT's established methodology of providing on-chain evidence with assertions. Users and counterparties should conduct independent due diligence. Separately, the metacoingraph.com reporting described the incident as a 'LaunchZone DeFi Protocol Suffers $700,000 Loss in Alleged Hack,' reinforcing the community-level uncertainty regarding whether the loss was an external hack or an insider action.","heading":"ZachXBT Flag and External Investigator Assessment","sources":[{"url":"https://metacoingraph.com/2023/02/27/launchzone-defi-protocol-suffers-700000-loss-in-alleged-hack/","name":"metacoingraph.com","type":"other","credibility":3},{"url":"https://en.wikipedia.org/wiki/ZachXBT","name":"en.wikipedia.org","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2020-12","event":"BSCex (BSCEX) launches on Binance Smart Chain as the first decentralized exchange ecosystem on BSC.","source":"","date_original":"2020-12-01"},{"date":"2021-03-14","event":"BSCEX rebrands to LaunchZone, pivoting toward a launchpad-first identity with IDO services, LZ Swap, LZ Pool, and LZ Wallet.","source":""},{"date":"2021-09-22","event":"LaunchZone announces partnership with IoTeX network to bring launchpad services and IDOs to the IoTeX ecosystem.","source":""},{"date":"2021-10","event":"Final vulnerable LaunchZone smart contract deployed (four contracts deployed between January and October 2021 later identified as carrying the access control flaw exploited in 2023).","source":"","date_original":"2021-10-01"},{"date":"2023-02-27","event":"Attacker (0x7d192fa3a48c307100c3e663050291fff786aa1f) exploits the Bscex SwapX contract, draining approximately $700,000 from LaunchZone's liquidity pool via PancakeSwap. The same attacker simultaneously exploits DungeonSwap for $728,000 and HFI for $18,940. LZ token price collapses 83-86%. Biswap delists LZ within hours.","source":""},{"date":"2023-02-27","event":"LaunchZone pauses trading and transfers of the LZ token. Team communicates via Telegram only, making no announcement to its 275,000 Twitter followers.","source":""},{"date":"2023-02-28","event":"LaunchZone discloses the SwapX vulnerability publicly, attributes attack to 'DND exploiter.' Community members raise rug pull allegations.","source":""},{"date":"2023-03-07","event":"LaunchZone announces compensation plan: affected users to receive $iRD tokens with a 15-month vesting period, convertible to $RD and stakeable for $USDC rewards.","source":""},{"date":"2023-03-26","event":"LaunchZone website (lz.finance) ceases operations. Protocol effectively defunct.","source":""},{"date":"2023-03-27","event":"Security researchers report 75,564 BSC wallet addresses remain exposed to the compromised contracts, with only 7,860 having revoked approvals. Total cumulative losses across all affected contracts reported at $7,792,137.","source":""}],"sources_used":[{"url":"https://iotex.io/blog/launchzone-partnership-ido-launchpad/","name":"iotex.io","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://cryptorank.io/fundraising-platforms/launch-zone","name":"cryptorank.io","type":"other","archive_url":"http://web.archive.org/web/20260829235349/https://cryptorank.io/fundraising-platforms/launch-zone","credibility":3,"archive_timestamp":"2026-08-29T23:53:49+00:00"},{"url":"https://www.bsc.news/post/launchzone-to-host-ido-for-play-to-earn-gamefi-project-stepheronft","name":"bsc.news","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://smartcontractshacking.com/hacks/launchzone-hack-2023","name":"smartcontractshacking.com","type":"other","archive_url":"https://web.archive.org/web/20260829141630/https://smartcontractshacking.com/hacks/launchzone-hack-2023","credibility":3,"archive_timestamp":"2026-08-29T14:16:30+00:00"},{"url":"https://medium.com/neptune-mutual/dungeon-swap-and-launch-zone-exploit-d9cb9c8b026","name":"medium.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://beincrypto.com/bnb-chain-protocol-launchzone-exploited-700k/","name":"beincrypto.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://u.today/75000-bsc-addresses-still-at-risk-after-launchzone-hack","name":"u.today","type":"other","archive_url":"http://web.archive.org/web/20250907182505/https://u.today/75000-bsc-addresses-still-at-risk-after-launchzone-hack","credibility":3,"archive_timestamp":"2025-09-07T18:25:05+00:00"},{"url":"https://cryptonews.net/news/security/20718794/","name":"cryptonews.net","type":"other","archive_url":"https://web.archive.org/web/20260829235012/https://cryptonews.net/news/security/20718794/","credibility":3,"archive_timestamp":"2026-08-29T23:50:12+00:00"},{"url":"https://protos.com/defi-project-launchzone-claims-to-be-latest-victim-of-bnb-chain-exploits/","name":"protos.com","type":"other","archive_url":"http://web.archive.org/web/20260413204822/https://protos.com/defi-project-launchzone-claims-to-be-latest-victim-of-bnb-chain-exploits/","credibility":3,"archive_timestamp":"2026-04-13T20:48:22+00:00"},{"url":"https://www.bitdegree.org/crypto/news/defi-protocol-launchzone-lost-around-300-000-in-a-liquidity-pool-exploit","name":"bitdegree.org","type":"other","archive_url":"https://web.archive.org/web/20260830003528/https://www.bitdegree.org/crypto/news/defi-protocol-launchzone-lost-around-300-000-in-a-liquidity-pool-exploit","credibility":3,"archive_timestamp":"2026-08-30T00:35:28+00:00"},{"url":"https://web3isgoinggreat.com/single/two-bnb-based-projects-attacked","name":"web3isgoinggreat.com","type":"other","archive_url":"http://web.archive.org/web/20251006221127/https://www.web3isgoinggreat.com/single/two-bnb-based-projects-attacked","credibility":3,"archive_timestamp":"2025-10-06T22:11:27+00:00"},{"url":"https://bscscan.com/token/0x3b78458981eb7260d1f781cb8be2caac7027dbe2","name":"bscscan.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://metacoingraph.com/2023/02/27/launchzone-defi-protocol-suffers-700000-loss-in-alleged-hack/","name":"metacoingraph.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-job","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://en.wikipedia.org/wiki/ZachXBT","name":"en.wikipedia.org","type":"other","archive_url":"http://web.archive.org/web/20260711020137/https://en.wikipedia.org/wiki/ZachXBT","credibility":3,"archive_timestamp":"2026-07-11T02:01:37+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:44.095635+00:00","updated_at":"2026-08-30T05:14:11.825397+00:00"}}