{"investigation":{"slug":"stablemagnet","entity_name":"StableMagnet","trust_score":2,"severity_base":null,"score_modifier":0,"confidence":0.92,"status":"published","content_type":"investigation","summary":"StableMagnet was a stablecoin yield and DEX protocol launched on Binance Smart Chain (BSC) that executed a deliberate rug pull on June 23-24, 2021, stealing approximately $27 million in USDT, USDC, and BUSD from over 1,000 users. The team concealed a malicious backdoor by substituting an unverified SwapUtils library for the one shown in publicly audited source code — a novel attack vector that exposed a critical gap in how block explorers verify linked library code. Following an anonymous white-hat investigation and Manchester police arrests, most of the stolen funds were eventually returned by late 2022.","sections":[{"content":"StableMagnet presented itself as a stablecoin-focused decentralized exchange and yield platform operating on Binance Smart Chain and Polygon. The protocol offered a 3Pool consisting of USDT, USDC, and BUSD, marketing high returns on stablecoin deposits to retail investors. The team operated anonymously, consistent with many DeFi projects launched in 2021, and obtained a smart contract audit from TechRate prior to launch. The project attracted over 1,000 depositors before its founders executed a coordinated exit. An unverified claim, reported by the Quadriga Initiative, alleged that members of the same team had previously been involved in similar exit scams on BSC under the names 'Moon Here' and 'WenMoon', though this connection was not independently corroborated at the time of the rug pull.","heading":"Overview and Background","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-stablemagnet-rugpull-june-2021","name":"halborn.com","type":"other","credibility":3},{"url":"https://rekt.news/stablemagnet-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.quadrigainitiative.com/casestudy/stablemagnetexitscam.php","name":"quadrigainitiative.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On June 23-24, 2021, the StableMagnet team activated a hidden backdoor and drained the protocol's 3Pool, removing approximately 8 million USDT, 7.2 million USDC, and 7 million BUSD — totaling roughly $22.2 million initially, with the total rising to $27 million as the backdoor was also used to sweep tokens from user wallets that had previously granted token approvals to the protocol. The attack exploited a novel and critical weakness: neither Etherscan nor BscScan verified the source code of linked library contracts at the time of the incident. The StableMagnet team deployed a malicious SwapUtils library at address 0xE25d05777BB4bD0FD0Ca1297C434e612803eaA9a, which was entirely different from the clean library code displayed in their public GitHub repository and in their block explorer listing. The deployed malicious library contained two capabilities: a function to drain all liquidity pool pairs, and a function to transfer tokens from every wallet that had ever approved the StableMagnet contract — regardless of whether those wallets had actively deposited funds. Security firm PeckShield was among the first to alert the community, noting on Twitter that StableMagnet's SwapUtils library code was unverified and different from the main swap contract, and urging users who had interacted with the protocol to revoke approvals immediately. Stolen funds were routed through the AnySwap/Multichain bridge from BSC to Ethereum, then converted from USDT to DAI, in a deliberate attempt to obscure the trail. On-chain analysis traced funds moving from the Binance hot wallet address 0x2bac04457e5de654cf1600b803e714c2c3fb96d7 to Ethereum addresses holding USDT and DAI.","heading":"The Rug Pull: Swapped Library Attack Vector","sources":[{"url":"https://rekt.news/stablemagnet-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-stablemagnet-rugpull-june-2021","name":"halborn.com","type":"other","credibility":3},{"url":"https://www.quadrigainitiative.com/casestudy/stablemagnetexitscam.php","name":"quadrigainitiative.com","type":"other","credibility":3},{"url":"https://x.com/peckshield/status/1407845381312892931","name":"x.com","type":"other","credibility":3},{"url":"https://smartcontractshacking.com/hacks/stablemagnet-hack-2021","name":"smartcontractshacking.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Prior to launch, StableMagnet underwent a smart contract security audit by TechRate, a firm that audited numerous BSC projects during the 2021 DeFi boom. The TechRate audit assessed the GitHub repository source code but did not verify that the linked library code actually deployed on-chain matched the reviewed code. Because the malicious SwapUtils library was not part of the GitHub source code TechRate reviewed, the audit provided no protection against the substituted library attack. TechRate was subsequently notified of the rug pull but allegedly took no immediate corrective action. The incident became a widely cited case study demonstrating that audit coverage of a project's GitHub repository — without verification against deployed bytecode and linked libraries — offers a false sense of security to users. The TechRate audit report for StableMagnet is archived in TechRate's public GitHub repository.","heading":"Audit Failure: TechRate","sources":[{"url":"https://github.com/TechRate/Smart-Contract-Audits","name":"github.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-stablemagnet-rugpull-june-2021","name":"halborn.com","type":"other","credibility":3},{"url":"https://rekt.news/stablemagnet-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://www.quadrigainitiative.com/casestudy/stablemagnetexitscam.php","name":"quadrigainitiative.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the rug pull, an anonymous white-hat hacker initiated a self-funded investigation into the identities of the StableMagnet team. According to reporting by CoinTelegraph and Bankless Times, the hacker examined the GitHub account associated with the project and used social network analysis to identify family members of suspected perpetrators, tracing the team to a group of individuals from Hong Kong. The investigator then tracked their travel movements to Chinatown in Manchester, United Kingdom. The white-hat hacker purchased a flight to Manchester and engaged local authorities. Manchester police responded and arrested at least some of the alleged perpetrators; investigators reportedly found a USB device containing approximately $9 million in funds. Following the arrests, other individuals allegedly connected to StableMagnet cooperated with the investigation and returned the majority of the remaining stolen funds. According to the Quadriga Initiative, approximately $24 million of the stolen assets were returned by December 1, 2022 — roughly eighteen months after the original theft. The white-hat investigator's identity has not been publicly disclosed.","heading":"Post-Incident Investigation and Arrests","sources":[{"url":"https://www.banklesstimes.com/news/2023/01/31/ethical-hacker-helps-recover-millions-lost-in-stablemagnet-rug-pull/","name":"banklesstimes.com","type":"other","credibility":3},{"url":"https://www.quadrigainitiative.com/casestudy/stablemagnetexitscam.php","name":"quadrigainitiative.com","type":"other","credibility":3},{"url":"https://www.cryptopolitan.com/defi-scammers-tracked-down-after-a-25-million-rug-pull/","name":"cryptopolitan.com","type":"other","credibility":3}],"severity":"medium"},{"content":"More than 1,000 user wallets suffered losses in the StableMagnet rug pull. Uniquely, the attack vector affected not only active liquidity providers but also any wallet that had previously granted a token approval to the StableMagnet contract — including users who had only performed test swaps or single interactions. Security researchers at Revoke.cash created an Exploit Checker tool specifically to help affected users determine whether their addresses were impacted and to revoke outstanding token approvals. The incident underscored the systemic risk of open-ended ERC-20/BEP-20 token approvals, as a single unlimited approval to a malicious contract can expose a wallet's entire balance of that token. All official StableMagnet websites and social media accounts were taken offline following the rug pull.","heading":"Impact on Users and Affected Wallets","sources":[{"url":"https://revoke.cash/exploits/stablemagnet","name":"revoke.cash","type":"other","credibility":3},{"url":"https://www.quadrigainitiative.com/casestudy/stablemagnetexitscam.php","name":"quadrigainitiative.com","type":"other","credibility":3},{"url":"https://www.web3isgoinggreat.com/?id=2021-06-23-0","name":"web3isgoinggreat.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The StableMagnet incident exposed a structural vulnerability in how major block explorers — Etherscan and BscScan — handled smart contract verification at the time. While these explorers marked contracts as 'verified' when submitted source code compiled to match the deployed bytecode, they did not separately verify that linked external library contracts also matched the source code claimed for those libraries. This allowed a malicious actor to show the public one library implementation while deploying an entirely different one. The exploit demonstrated that even a 'verified' smart contract on a block explorer could contain hidden malicious functionality if that functionality resided in an unverified linked library. Security firm Halborn published a detailed post-mortem analyzing this vector and recommending that investors not rely solely on block explorer verification or incomplete audits. The case is widely referenced in DeFi security literature as an example of why full bytecode verification across all linked dependencies is necessary.","heading":"Systemic Risk: Block Explorer Library Verification Gap","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-stablemagnet-rugpull-june-2021","name":"halborn.com","type":"other","credibility":3},{"url":"https://rekt.news/stablemagnet-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://x.com/peckshield/status/1407845381312892931","name":"x.com","type":"other","credibility":3}],"severity":"medium"},{"content":"StableMagnet is listed among entities flagged by the on-chain investigator community, including ZachXBT. While no dedicated ZachXBT investigation report on StableMagnet was located in public archives, the incident received significant coverage from crypto security researchers and investigative accounts active in 2021. PeckShield, an on-chain security firm with credibility comparable to ZachXBT's analytical work, issued real-time alerts on Twitter during the exploit, advising users to revoke approvals. The case is included in AVOID.NET's high-risk registry based on its confirmed status as a deliberate fraud, the scale of losses, and the use of a premeditated technical deception to circumvent audit and explorer verification processes.","heading":"ZachXBT and Community Flagging","sources":[{"url":"https://x.com/peckshield/status/1407845381312892931","name":"x.com","type":"other","credibility":3},{"url":"https://rekt.news/stablemagnet-rekt","name":"rekt.news","type":"other","credibility":3}],"severity":"medium"},{"content":"The following on-chain addresses are associated with the StableMagnet exploit and fund movement, as identified by PeckShield, Rekt News, and independent researchers. The malicious SwapUtils library was deployed at 0xE25d05777BB4bD0FD0Ca1297C434e612803eaA9a on BSC. The StableMagnet Swap contract address is 0xb89e9365cb5bacfcf4a4b0386dfad45c3b4d3258 on BSC. Initial exploit transaction: 0xf0ba46c8a20e1e75ad382e42c509bf71393e1b3b90326165c747a5d3cc5d967c. Funds were bridged via AnySwap to Ethereum, passing through 0x2bac04457e5de654cf1600b803e714c2c3fb96d7 (identified as a Binance hot wallet used as a layering hop), then onward to Ethereum USDT address 0xDF5B180c0734fC448BE30B7FF2c5bFc262bDEF26 and DAI address 0xe5daac909a3205f99d370bc2b32b1810a4912a07.","heading":"On-Chain Addresses of Interest","sources":[{"url":"https://rekt.news/stablemagnet-rekt","name":"rekt.news","type":"other","credibility":3},{"url":"https://bscscan.com/address/0xb89e9365cb5bacfcf4a4b0386dfad45c3b4d3258","name":"bscscan.com","type":"other","credibility":3},{"url":"https://x.com/peckshield/status/1407845381312892931","name":"x.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2021-06","event":"StableMagnet launches on Binance Smart Chain, offering a USDT/USDC/BUSD 3Pool stablecoin DEX with a TechRate audit in place.","source":"","date_original":"2021-06-01"},{"date":"2021-06-23","event":"StableMagnet team activates malicious backdoor in the unverified SwapUtils library (0xE25d05777BB4bD0FD0Ca1297C434e612803eaA9a), draining approximately $22.2 million in USDT, USDC, and BUSD from the 3Pool and sweeping tokens from wallets with open approvals. Total losses reach approximately $27 million.","source":""},{"date":"2021-06-24","event":"PeckShield alerts the crypto community on Twitter that StableMagnet's SwapUtils library is unverified and different from the main swap contract source code, urging users to revoke approvals immediately. Rekt News publishes a detailed post-mortem.","source":""},{"date":"2021-06-24","event":"Stolen funds are bridged from BSC to Ethereum via AnySwap/Multichain and converted from USDT to DAI in an apparent laundering attempt. All StableMagnet websites and social media accounts go offline.","source":""},{"date":"2021-07","event":"Halborn publishes detailed technical analysis of the library substitution attack vector, noting the structural verification gap in Etherscan and BscScan.","source":"","date_original":"2021-07-01"},{"date":"2022-01-30","event":"An anonymous white-hat hacker goes public (via CoinTelegraph and Bankless Times coverage) with details of their investigation: they identified alleged perpetrators as Hong Kong-based individuals, tracked their travel to Manchester, UK, and cooperated with Manchester police, who arrested suspects and recovered approximately $9 million from a USB device.","source":""},{"date":"2022-12","event":"Approximately $24 million of the originally stolen $27 million is reported returned to victims, following arrests and cooperation from alleged co-conspirators, per Quadriga Initiative records.","source":"","date_original":"2022-12-01"}],"sources_used":[{"url":"https://www.halborn.com/blog/post/explained-the-stablemagnet-rugpull-june-2021","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260516232117/https://www.halborn.com/blog/post/explained-the-stablemagnet-rugpull-june-2021","credibility":3,"archive_timestamp":"2026-05-16T23:21:17+00:00"},{"url":"https://rekt.news/stablemagnet-rekt","name":"rekt.news","type":"other","archive_url":"http://web.archive.org/web/20260607075620/https://rekt.news/stablemagnet-rekt","credibility":3,"archive_timestamp":"2026-06-07T07:56:20+00:00"},{"url":"https://www.quadrigainitiative.com/casestudy/stablemagnetexitscam.php","name":"quadrigainitiative.com","type":"other","archive_url":"http://web.archive.org/web/20260417185311/https://quadrigainitiative.com/casestudy/stablemagnetexitscam.php","credibility":3,"archive_timestamp":"2026-04-17T18:53:11+00:00"},{"url":"https://x.com/peckshield/status/1407845381312892931","name":"x.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://smartcontractshacking.com/hacks/stablemagnet-hack-2021","name":"smartcontractshacking.com","type":"other","archive_url":"https://web.archive.org/web/20260829195200/https://smartcontractshacking.com/hacks/stablemagnet-hack-2021","credibility":3,"archive_timestamp":"2026-08-29T19:52:00+00:00"},{"url":"https://github.com/TechRate/Smart-Contract-Audits","name":"github.com","type":"other","archive_url":"http://web.archive.org/web/20260708022516/https://github.com/TechRate/Smart-Contract-Audits","credibility":3,"archive_timestamp":"2026-07-08T02:25:16+00:00"},{"url":"https://www.banklesstimes.com/news/2023/01/31/ethical-hacker-helps-recover-millions-lost-in-stablemagnet-rug-pull/","name":"banklesstimes.com","type":"other","archive_url":"http://web.archive.org/web/20260607230107/https://www.banklesstimes.com/news/2023/01/31/ethical-hacker-helps-recover-millions-lost-in-stablemagnet-rug-pull/","credibility":3,"archive_timestamp":"2026-06-07T23:01:07+00:00"},{"url":"https://www.cryptopolitan.com/defi-scammers-tracked-down-after-a-25-million-rug-pull/","name":"cryptopolitan.com","type":"other","archive_url":"http://web.archive.org/web/20251211051115/https://www.cryptopolitan.com/defi-scammers-tracked-down-after-a-25-million-rug-pull/","credibility":3,"archive_timestamp":"2025-12-11T05:11:15+00:00"},{"url":"https://revoke.cash/exploits/stablemagnet","name":"revoke.cash","type":"other","archive_url":"http://web.archive.org/web/20260416233829/https://revoke.cash/exploits/stablemagnet","credibility":3,"archive_timestamp":"2026-04-16T23:38:29+00:00"},{"url":"https://www.web3isgoinggreat.com/?id=2021-06-23-0","name":"web3isgoinggreat.com","type":"other","archive_url":"https://web.archive.org/web/20260830094150/https://www.web3isgoinggreat.com/?id=2021-06-23-0","credibility":3,"archive_timestamp":"2026-08-30T09:41:50+00:00"},{"url":"https://bscscan.com/address/0xb89e9365cb5bacfcf4a4b0386dfad45c3b4d3258","name":"bscscan.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:56.508256+00:00","updated_at":"2026-08-30T13:44:40.386081+00:00"}}