{"investigation":{"slug":"mobius-token","entity_name":"Mobius Token","trust_score":18,"severity_base":null,"score_modifier":0,"confidence":0.85,"status":"published","content_type":"investigation","summary":"Mobius Token (ticker: MBU) is a DeFi token that operated on BNB Chain. On May 11, 2025, an attacker exploited a critical decimal-precision bug in the project's unaudited smart contract, minting approximately 9.73 quadrillion MBU tokens with a deposit of only 0.001 BNB and draining $2.15 million in USDT from the protocol's liquidity pools. The stolen funds were laundered through Tornado Cash, no official team response was issued, and no funds have been recovered.","sections":[{"content":"On May 11, 2025, at approximately 07:31 UTC, an attacker deployed a malicious smart contract on BNB Chain targeting Mobius Token's (MBU) deposit and minting logic. Within two minutes of deployment, the attacker executed the exploit and drained $2,152,219.99 from the protocol. The attack was first detected and publicized by Web3 security firm Cyvers, which flagged the malicious contract deployment in real time. Security firm CertiK and auditor QuillAudits subsequently published post-mortem analyses confirming the root cause. The attacker's address (0xB32A53Af96F7735D47F4b76C525BD5Eb02B42600) had been funded with 10 BNB via Tornado Cash on May 4, 2025 — the same wallet had also allegedly exploited MHT Trade on that date. The attacker contract address was 0x631adFF068D484Ce531Fb519Cda4042805521641. The exploit transaction hash is 0x2a65254b41b42f39331a0bcc9f893518d6b106e80d9a476b8ca3816325f4a150. After the exploit, the attacker converted the minted MBU to USDT via PancakeSwap liquidity pools, crashing the MBU token price to near zero, then laundered approximately 2,100 BNB through Tornado Cash in 21 batches of 100 BNB each.","heading":"Smart Contract Exploit (May 2025)","sources":[{"url":"https://cointelegraph.com/news/mobius-token-exploit-bnb-chain-2-1m-loss","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/mobius-token-incident-analysis","name":"certik.com","type":"other","credibility":3},{"url":"https://www.quillaudits.com/blog/hack-analysis/mobius-token-exploit-breakdown","name":"quillaudits.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-mobius-hack-may-2025","name":"halborn.com","type":"other","credibility":3},{"url":"https://beincrypto.com/mobius-defi-hack-on-bnb-chain/","name":"beincrypto.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Multiple security researchers independently confirmed that the root cause of the exploit was a critical decimal-precision error (a '1e18 inflation bug') in the token minting function. The contract's internal price function `_getBNBPriceInUSDT` returned a value already denominated in 18 decimal places, but the minting logic then multiplied this value by 10^18 a second time. This double-multiplication massively inflated the perceived value of collateral deposited by the attacker, allowing the contract to mint a near-unlimited number of tokens. With a deposit of only 0.001 WBNB (worth approximately $0.67), the attacker successfully minted 9,731,099,570,720,980.659843835099042677 MBU tokens — approximately 9.73 quadrillion. Security analysts at QuillAudits and Halborn noted the attack could have been prevented through basic testing of the token minting function and implementation of minting caps. The vulnerable contract (0x637D8Ce897bb653cb83bA436CDf76bBe158f05B1) was reportedly unaudited prior to deployment.","heading":"Vulnerability: Decimal Inflation Bug","sources":[{"url":"https://www.quillaudits.com/blog/hack-analysis/mobius-token-exploit-breakdown","name":"quillaudits.com","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/mobius-token-incident-analysis","name":"certik.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-mobius-hack-may-2025","name":"halborn.com","type":"other","credibility":3},{"url":"https://quillaudits.medium.com/mobius-token-exploit-breakdown-2-1m-lost-due-to-poor-logic-4c5ea5febdec","name":"quillaudits.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"CertiK's post-incident analysis noted that the Mobius Token contract belongs to a cohort of unaudited DeFi projects that suffered exploits in 2025. According to CertiK, 46 unaudited projects suffered exploits in 2025 with combined losses of $6.4 million, and Mobius Token was among these. The absence of a third-party security audit prior to deployment is cited by multiple analysts as the primary preventable failure. QuillAudits assessed that simple unit tests around token minting logic would have caught the double-multiplication error before launch. The vulnerable contract is described by researchers as having poor input validation and no minting caps as safeguards.","heading":"Unaudited Contract and Security Failures","sources":[{"url":"https://www.certik.com/resources/blog/mobius-token-incident-analysis","name":"certik.com","type":"other","credibility":3},{"url":"https://www.quillaudits.com/blog/hack-analysis/mobius-token-exploit-breakdown","name":"quillaudits.com","type":"other","credibility":3},{"url":"https://beincrypto.com/mobius-defi-hack-on-bnb-chain/","name":"beincrypto.com","type":"other","credibility":3}],"severity":"medium"},{"content":"As of the available reporting following the May 11, 2025 exploit, the Mobius Token team had not released any official public statement acknowledging the breach. No incident response, compensation plan, or post-mortem from the project team has been documented in major crypto news outlets. The attacker's wallet retained the stolen funds, and the 2,100 BNB laundered through Tornado Cash had not produced corresponding withdrawal activity as of initial reports. No fund recovery, white-hat contact, or law enforcement coordination was reported.","heading":"Team Response and Fund Recovery","sources":[{"url":"https://beincrypto.com/mobius-defi-hack-on-bnb-chain/","name":"beincrypto.com","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/mobius-token-incident-analysis","name":"certik.com","type":"other","credibility":3},{"url":"https://www.cryptopolitan.com/mobius-suffers-hack-on-bnb-chain/","name":"cryptopolitan.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, third-party scammers alleged to have created fraudulent 'MOT' tokens on BEP20 and other low-cost chains, airdropping small amounts to wallet addresses to attract victims. Reports indicate that fake airdrop campaigns and phishing websites have circulated in the aftermath, falsely claiming to distribute MBU or MOT tokens. These secondary scams are distinct from the original smart contract exploit but exploit the confusion generated by the hack and the project's collapse.","heading":"Associated Scam Activity","sources":[{"url":"https://thespotlite.net/mobius-finance-mot-airdrop-is-it-real-or-a-scam-full-details","name":"thespotlite.net","type":"other","credibility":3},{"url":"https://cryptorank.io/news/feed/a08b2-mobius-exploited-for-2-1m-while-scammers-breach-ledgers-social-media","name":"cryptorank.io","type":"other","credibility":3}],"severity":"medium"},{"content":"No SEC, CFTC, DOJ, or other regulatory actions have been publicly identified against Mobius Token (MBU) or its operators as of May 2026. The exploit has not been linked to any public law enforcement investigation. The use of Tornado Cash to launder the stolen funds is consistent with patterns seen in other DeFi exploits where funds remain unrecovered.","heading":"Regulatory and Law Enforcement Status","sources":[{"url":"https://www.certik.com/resources/blog/mobius-token-incident-analysis","name":"certik.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2025-05-04","event":"Attacker wallet 0xB32A53Af96F7735D47F4b76C525BD5Eb02B42600 funded via Tornado Cash with 10 BNB; same wallet allegedly exploited MHT Trade on this date.","source":""},{"date":"2025-05-08","event":"Mobius Token contract reportedly funded in preparation for the exploit.","source":""},{"date":"2025-05-11","event":"At 07:31 UTC, attacker deployed malicious contract 0x631adFF068D484Ce531Fb519Cda4042805521641 on BNB Chain.","source":""},{"date":"2025-05-11","event":"At 07:33 UTC, exploit executed: 0.001 WBNB deposited, approximately 9.73 quadrillion MBU tokens minted via decimal inflation bug, and $2,152,219.99 in USDT drained from PancakeSwap liquidity pools.","source":""},{"date":"2025-05-11","event":"Security firm Cyvers publicly flagged the exploit in real time on X (Twitter). CertiK, QuillAudits, and Halborn published post-mortem analyses.","source":""},{"date":"2025-05-11","event":"Attacker laundered approximately 2,100 BNB through Tornado Cash in 21 batches of 100 BNB. MBU token price collapses to near zero.","source":""},{"date":"2025-05-11","event":"No official statement released by the Mobius Token team. No fund recovery reported.","source":""}],"sources_used":[{"url":"https://cointelegraph.com/news/mobius-token-exploit-bnb-chain-2-1m-loss","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260720144132/https://cointelegraph.com/news/mobius-token-exploit-bnb-chain-2-1m-loss","credibility":3,"archive_timestamp":"2026-07-20T14:41:32+00:00"},{"url":"https://www.certik.com/resources/blog/mobius-token-incident-analysis","name":"certik.com","type":"other","archive_url":"http://web.archive.org/web/20260220020347/https://www.certik.com/resources/blog/mobius-token-incident-analysis","credibility":3,"archive_timestamp":"2026-02-20T02:03:47+00:00"},{"url":"https://www.quillaudits.com/blog/hack-analysis/mobius-token-exploit-breakdown","name":"quillaudits.com","type":"other","archive_url":"http://web.archive.org/web/20260515104309/https://www.quillaudits.com/blog/hack-analysis/mobius-token-exploit-breakdown","credibility":3,"archive_timestamp":"2026-05-15T10:43:09+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-mobius-hack-may-2025","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260605225819/https://www.halborn.com/blog/post/explained-the-mobius-hack-may-2025","credibility":3,"archive_timestamp":"2026-06-05T22:58:19+00:00"},{"url":"https://beincrypto.com/mobius-defi-hack-on-bnb-chain/","name":"beincrypto.com","type":"other","archive_url":"http://web.archive.org/web/20260225053952/https://beincrypto.com/mobius-defi-hack-on-bnb-chain/","credibility":3,"archive_timestamp":"2026-02-25T05:39:52+00:00"},{"url":"https://quillaudits.medium.com/mobius-token-exploit-breakdown-2-1m-lost-due-to-poor-logic-4c5ea5febdec","name":"quillaudits.medium.com","type":"other","archive_url":"http://web.archive.org/web/20251017163050/https://quillaudits.medium.com/mobius-token-exploit-breakdown-2-1m-lost-due-to-poor-logic-4c5ea5febdec","credibility":3,"archive_timestamp":"2025-10-17T16:30:50+00:00"},{"url":"https://www.cryptopolitan.com/mobius-suffers-hack-on-bnb-chain/","name":"cryptopolitan.com","type":"other","archive_url":"https://web.archive.org/web/20260829122014/https://www.cryptopolitan.com/mobius-suffers-hack-on-bnb-chain/","credibility":3,"archive_timestamp":"2026-08-29T12:20:14+00:00"},{"url":"https://thespotlite.net/mobius-finance-mot-airdrop-is-it-real-or-a-scam-full-details","name":"thespotlite.net","type":"other","archive_url":"http://web.archive.org/web/20260517235301/https://thespotlite.net/mobius-finance-mot-airdrop-is-it-real-or-a-scam-full-details","credibility":3,"archive_timestamp":"2026-05-17T23:53:01+00:00"},{"url":"https://cryptorank.io/news/feed/a08b2-mobius-exploited-for-2-1m-while-scammers-breach-ledgers-social-media","name":"cryptorank.io","type":"other","archive_url":"https://web.archive.org/web/20260829114138/https://cryptorank.io/news/feed/a08b2-mobius-exploited-for-2-1m-while-scammers-breach-ledgers-social-media","credibility":3,"archive_timestamp":"2026-08-29T11:41:38+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:23.599938+00:00","updated_at":"2026-08-29T12:34:19.09918+00:00"}}