Nine Days, One Leaked Key: How GANA Payment Lost $3.1M on BNB Chain
GANA Payment, a payment protocol that had only just gone live on BNB Smart Chain, lost $3.1 million before its staking product had a chance to build any real track record.
There was no oracle manipulation and no elaborate contract logic to unpick. According to QuillAudits' review, the intruder simply combined an EIP-7702 delegator contract with a compromised owner private key, then cycled the staking system's stake-and-unstake mechanism to siphon funds repeatedly.

The protocol had gone live on November 11 and was drained on November 20 — nine days later, with no audit ever completed and no real window for users to evaluate the platform.
Roughly 90% of token value was wiped out as the stolen funds fanned out across networks: about $2.1 million was bridged to Ethereum, while the remainder stayed on BSC, largely funneled through Tornado Cash. A further 346 ETH sat untouched for a time before eventually moving as well.
ZachXBT was the first to surface the incident, with QuillAudits and Blockscope subsequently mapping out the laundering, which continued in deliberate, staggered batches.
01Timeline and disclosure
ZachXBT posted the consolidation address in the early hours of November 20, well before the broader crypto community had woken up to the news. By the time GANA Payment issued its "urgent announcement" confirming a breach, the attacker had already moved 1,140 BNB (about $1.04 million) into Tornado Cash on BSC and begun bridging the rest toward Ethereum.
The team's statement read: "GANA's interaction contract has been targeted by an external attack, resulting in unauthorized asset theft." Community members were quick to push back on that framing — one reply argued that the real cause was private-key leakage, not some abstract "interaction contract" being targeted.
GANA subsequently pledged an emergency investigation with an outside security firm, alongside a full reboot roadmap and a complete accounting of remaining assets.
02How EIP-7702 was turned against the protocol
SlowMist founder Yu Xian summarized the mechanics: the owner's private key was exposed, an EIP-7702 delegator contract was deployed against it, and this let the attacker bypass the onlyEOA check that was meant to restrict the unstake function to regular wallets. No conventional hack or price manipulation was required — whoever held the key effectively held the protocol.
EIP-7702 was designed as an Ethereum upgrade allowing externally owned accounts to temporarily take on smart-contract-like behavior, enabling features such as batched transactions, sponsored gas, and delegated permissions. In this case, the malicious delegator contract sat between the stolen owner key and GANA's staking contract, acting as the mechanism that let the attacker act with owner-level authority.
Malicious delegator contract: 0x7A44bD9C6095Ca7b2A6f62FE65b81924c6cAb067
GANA's staking contract: 0xACF753d5d81462db45b7f024e9fa76993ce9bcfb
Per GoPlus Security's assessment, the attacker likely obtained admin access through social engineering or phishing, then repeatedly called transferOwnership to cycle through eight pre-staged addresses. Each rotation authorized the EIP-7702 delegator to bypass the onlyEOA restriction guarding the unstake function.
Hacken's investigation described the pattern in more detail: the attacker staked GANA and USDT across seven separate accounts, then withdrew everything through the delegated contract using a single EIP-7702 transaction. Just before withdrawing, the reward parameter for gana_Computility was reset to an artificially inflated rate of 10,000,000,000,000,000, manipulating the payout logic in the attacker's favor.
The scheme relied on eight repeated cycles funneling into a single point.
Primary consolidation address: 0x2e8a8670b734e260cedbc6d5a05532264aae5c38
Because the withdrawal was executed with legitimate owner privileges, the smart contract itself had no way to distinguish an authorized reward payout from a manufactured theft.
03Tracing the stolen funds
Key on-chain markers from the incident:
Victim staking contract: 0xACF753d5d81462db45b7f024e9fa76993ce9bcfb
Malicious EIP-7702 delegator: 0x7A44bD9C6095Ca7b2A6f62FE65b81924c6cAb067
Ownership transfer (immediately preceding the drain): 0x8f909383a91c55282a59a1568a9ca58f7e4a02d26f1918dfc5c641a99bdabda8
Sample stake transaction: 0xac935e62f3f6f375d856775f8fe2628e92b1944b15a251090bef213dc5f5f9e2
Main exploit transaction (unstake plus delegator): 0x0a1fabbb536cf776335e2ded5ebf70f4c9601376e7265a127afe55305eff69ad
Primary BSC consolidation address: 0x2e8a8670b734e260cedbc6d5a05532264aae5c38
From there, stolen tokens were swapped for liquid assets and the operation split across two chains.
On BSC: 1,140 BNB (roughly $1.04 million) went to Tornado Cash directly. A secondary BSC address handled the remaining roughly $1 million before it, too, moved toward Tornado Cash: 0xd10Ed57534Dc63f2ea9dC0cB0096086F3CC8fA4d.
Separately, about $2.1 million was bridged to Ethereum using deBridge and Stargate.
Initial landing address on Ethereum: 0x5149A7696188F083297281D10293a20476252CDD
Distribution wallets (flagged by Blockscope): 0x7a503e3ab9433ebf13afb4f7f1793c25733b3cca and 0x98fc13632ff112e4667fc4f21ae980571f122b5a
346.8 ETH (about $1.05 million) eventually moved to Tornado Cash on Ethereum, though one address — 0x7a503e3ab9433ebf13afb4f7f1793c25733b3cca — held 346 ETH dormant for several hours first.

The laundering then proceeded gradually, moving through Tornado Cash in tranches of 1 ETH, 10 ETH, and 100 ETH — a pacing likely intended to make the flow harder for investigators to follow.
04Part of a broader pattern on BSC
GANA Payment had launched on November 11 without a public audit or published security documentation, and nine days later became another entry in BSC's list of mid-sized exploits.
The disparity in audit coverage is notable: only about 41% of smart contracts deployed on BSC in 2025 have been audited, compared with roughly 74% on Ethereum — a 33-percentage-point gap.
DefiLlama's hack tracker shows BSC-based projects losing more than $200 million to exploits in 2025 alone, with KiloEx, Seedify, GriffinAI, and Woo X among the casualties. Phemex separately lost $85 million, and Nobitex was hit for $82 million. GANA Payment now joins that list.
The trend runs counter to earlier progress: BNB Chain had touted a 70% drop in exploit losses, from $161 million in 2023 down to $47 million in 2024. That improvement reversed sharply in 2025, with losses across twelve exploits topping $200 million — more than four times the 2024 total.
GANA's token dropped roughly 90% within 24 hours of the exploit; DexScreener data shows the price falling from $2.98 to $0.31.
On November 24, the GANA Foundation announced a reboot plan that includes securing 100% of remaining capital for ecosystem recovery, rebuilding the token's bottom liquidity pool, and outlining a detailed compensation framework.
05The unanswered question
What the reboot plan does not address is how a protocol that launched without an audit, was compromised within nine days, and was drained through a well-documented exploit pattern earns a second chance to hold user funds.
In summary: the exploit unfolded across nine days from launch to drain, using a leaked owner key, an EIP-7702 delegator contract, and eight rotations of ownership to bypass the onlyEOA restriction — all recorded transparently on-chain, down to the ownership transfers, the inflated reward rate, and the cross-chain laundering route. GANA has promised secured capital, a rebuilt token pool, and compensation, but that leaves open why a version 2.0 of the protocol should be trusted when version 1.0 didn't survive its first nine days.
Get new scam files the moment we publish them — usually 2–3 emails a week.