CryptoReal
CASE FILE — Sep 26, 2025

Spoofed LayerZero Peer Lets Attacker Mint 5 Billion Fake GAIN Tokens, Crashing Griffin AI Days After Launch

Less than a day after debuting on Binance Alpha, the Web3 AI project Griffin AI saw its token economics collapse under a wave of unauthorized inflation.

An attacker manipulated LayerZero's cross-chain trust settings so that a counterfeit Ethereum contract was accepted as a legitimate peer, then used that access to mint 5 billion unbacked $GAIN tokens. Only 2.8% of that haul was sold off, netting roughly $3 million — but the remaining 97.2% still hangs over the market as a standing threat to whatever value is left in $GAIN.

Griffin AI's founder later published a full, unqualified acknowledgment of the failure, but taking responsibility doesn't repair the tokenomics or explain how the underlying cross-chain permissions were compromised in the first place.

Credit: Wu Blockchain, Oliver Feldmeier, Blockscope, GoPlus, CertiK, Peckshield, GriffinAI, Blocksec Phalcon, Bitget, Cryptopolitan, Bein Crypto, Ember CN, bitcoinethereumnews, Noah Mateo

01Early Warnings

GoPlus Security was the first to flag the issue on September 24th, reporting that Griffin AI — freshly listed on Binance Alpha — had suffered malicious minting that pushed 5 billion additional tokens into circulation against a stated maximum supply of 1 billion, sending $GAIN's price down more than 90%.

GoPlus followed with a screenshot documenting the mint that put total supply at five times the intended cap, and urged users to avoid interacting with the project until the situation was resolved.

CertiK's account of the mechanism was direct: the attacker set up a fraudulent LayerZero peer on Ethereum, then used it to bridge 5 billion fake tokens, minting an equivalent 5 billion $GAIN on BNB Chain.

PeckShield traced the resulting cash-out: 147.5 million $GAIN was sold for 2,955 BNB, which was then bridged to Ethereum and converted into 720 ETH, of which 700 ETH was routed to Tornado Cash. Blockscope published a map of the cross-chain laundering trail while the funds were still in motion — independent researchers had reconstructed the attack before Griffin AI itself had issued any real explanation.

02Griffin AI's Response Timeline

Griffin AI's first public statement came roughly 22 minutes after GoPlus's initial alert: "We are investigating the issue and will make a detailed post as soon as we have more information." The message gave no indication of scale and offered no direct warning to holders.

Just over an hour later, founder Oliver Feldmeier posted a more technical explanation: an unauthorized LayerZero peer configuration had let the attacker deploy a fraudulent Ethereum-based contract (a token labeled $TTTTT at address 0x7a8caf) and use it to mint 5 billion GAIN on BNB Chain.

The following day, Feldmeier posted a fuller apology: "This is an incredibly difficult day, and I want to start by offering my deepest, most sincere apologies to the entire Griffin AI community," writing that the breach happened "on my watch" and accepting full responsibility. He also announced plans to migrate to an entirely new, audited token, with balances to be restored based on snapshots taken before the exploit — effectively conceding that the original token could not be salvaged.

The open question isn't only how LayerZero's trust mechanism was fooled, but how the attacker obtained the administrative access needed to fool it — whether through phishing, a paid insider, or simple negligence around key custody.

03How the Peer Was Spoofed

At the center of the exploit was LayerZero's peer-trust configuration, which the attacker turned into an unauthorized minting mechanism. A decoy contract at 0x7a8CAffeb11047E90Affc9F7527103b0334572E6 stood in for the legitimate GAIN endpoint located at 0xccdbb9c8e43f50407c58f81407a16549e2a475dd.

The method: deploy a fake $TTTTT token on Ethereum, register it as the LayerZero peer in place of the real endpoint, and let the bridge treat deposits into that fake contract as legitimate cross-chain transfers.

Sums referenced in this case file

According to Blocksec Phalcon, the attacker got a compromised admin address to call the setPeer function — possibly obtained through phishing — designating the malicious contract as a trusted peer and thereby enabling unrestricted minting across the bridge.

No collateral, deposit verification, or backing was required — the admin key alone was enough to hold minting rights for days. Griffin AI's bridge infrastructure had no way to distinguish authentic cross-chain messages from fabricated ones, and duly minted 5 billion GAIN against phantom Ethereum-side deposits.

5 billion GAIN mint transaction: 0xa85b18bdbd32fbe5468de38032f7f2717faaad663d33991b2c71ce0b3892e866

Blocksec Phalcon noted this wasn't an isolated case: "Yet another attack targeting Griffin AI similar to the Seedifyfund incident: fraudulent cross-chain messages from the source chain were accepted and executed on the destination chain." GoPlus Security drew a similar comparison to an earlier attack on the Yala project, which also used fake LayerZero peers to bypass cross-chain checks. The same peer-trust flaw has now been exploited across Seedify, Yala, and Griffin AI.

04Tracing the Funds

The mint took Griffin AI's total supply from 1 billion to 5.2985 billion tokens, all controlled by a single attacker address: 0xf3d17326130f90c1900bc0b69323c4c7e2d58db2.

Of the 5 billion minted tokens, only 147.5 million — about 2.8% of the total — were sold, which was still enough to drive GAIN's price down 90% given shallow liquidity on PancakeSwap, and yielded roughly 2,955 BNB, worth about $3 million, to the attacker. The remaining 4.85 billion tokens remain unsold, still sitting in the attacker's wallet.

Attacker's wallet on Arkham (unlabeled as of writing): 0xF3d17326130F90c1900bc0B69323C4C7E2d58Db2

The stolen BNB was bridged to Ethereum via deBridge across six separate transactions:

A portion of the funds subsequently reached Tornado Cash. Per EmberCN's tracking, the 2,955 BNB converted through deBridge into approximately 720 ETH, which was then split across six wallets — five holding 100 ETH each and one holding 200 ETH:

The sixth wallet, 0xf1755A2b7d0e418E9BAB4F81AD674fa39fA7F23D, received 200 ETH and still holds 20 ETH.

05Emergency Response

Within an hour of identifying the exploit, Griffin AI pulled its official liquidity pools from BNB Chain. "Please DO NOT interact with any LPs that may be created by the attacker. They are not official and pose a risk," the team warned. Daily trading volume spiked 126% to $96 million as holders rushed to exit.

Griffin AI said it was "coordinating closely with exchanges and security partners" and asked exchanges to pause GAIN trading; KuCoin and MEXC responded by suspending deposits, withdrawals, and trading. The project also ended its ongoing airdrop campaigns in the wake of the exploit, though the already-completed Binance Alpha airdrop was unaffected.

06Context

Hours before the exploit, GAIN had been in the middle of a "price-discovery tear," with $109.8 million in launch-day volume and chatter about a run toward $0.20 resistance. By the following morning, that momentum had been replaced by a 90% price collapse.

The incident follows closely on the heels of UXLink's multisig compromise, which cost users $41 million — another case where administrative access, rather than a code-level bug, became the point of failure. Notably, the same address behind the Griffin AI exploit later minted trillions of counterfeit UXLink tokens across three transactions, using a fake contract deployed on September 23rd.

Griffin AI's founder has taken unusually direct ownership of the incident, but that doesn't undo the fact that a single compromised admin key was enough to turn a cross-chain bridge into an unlimited minting tool. The 4.85 billion unsold tokens still held in the attacker's wallet mean the risk to remaining holders has not passed — it has simply not yet been realized.

Admin PrivilegesGriffinAI
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.