Lookonchain APP

App Store

BNB (BNB) — Onchain News & Whale Tracking

Real-time BNB whale movements, exchange flows and onchain findings tracked by Lookonchain. 609 updates and counting.

2026.08.21 21:20

BounceBit Chain Releases Update on Vulnerability Attack Progress: Will Permanently Halt the Chain and Migrate to BNB Chain

Cross-chain yield protocol BounceBit has released a security incident notice, stating its blockchain network suffered a protocol-level vulnerability attack from 21:02 UTC on August 19 to 01:54 UTC on August 20. Attackers exploited an authorization flaw in Evmos’ underlying architecture to transfer BB tokens from 9 mainnet accounts without account owners’ authorization. Per the notice, the attackers moved approximately 286.5 million BB via 14 transactions. The incident is limited to BounceBit Chain itself, with no involvement of private key leaks, signature forgery, wallet, hardware device, or exchange account security issues. BounceBit’s CeDeFi Strategy, Promo Vaults, Prime, and RWA products were all unaffected. BounceBit noted the vulnerability stemmed from an authorization validation flaw in Evmos’ protocol-native module. When the attacker called the relevant module via a smart contract, they bypassed the security check that should verify the fund source account’s authorization, allowing them to designate any account as the fund source. After the incident, BounceBit Chain stopped block production at block height 20,702,857. The team decided not to perform a chain upgrade, instead permanently shutting down BounceBit Chain and reissuing BB as a BNB Chain-based BEP-20 token. The new BB supply will be based on an on-chain snapshot taken before the first abnormal transfer (block height 20,697,260). The 286,543,148 BB tokens transferred by attackers will not be included in new balances. Users do not need to submit applications or migrate wallets; the official will automatically distribute new BB to corresponding BNB Chain addresses.

2026.08.07 10:56

Microsoft: Discovers new attack campaign hiding malicious code via BNB Chain smart contracts, affecting thousands of devices globally.

Microsoft’s Threat Intelligence Team has released a report disclosing a set of compromised websites that use ClickFix and TerminalFix to launch social engineering attacks, combined with EtherHiding technology, to access smart contracts via the BNB Smart Chain RPC gateway for retrieving subsequent malicious commands. Since the malicious content is stored in on-chain smart contracts, only the wallet owner that deployed the contract can modify it, making it hard to eliminate through traditional takedown or blocking measures. Attackers forge CAPTCHA verification pages to trick users into opening Windows’ Run window, Terminal, or PowerShell, then pasting and executing malicious commands. The attack workflow extensively leverages system tools including conhost, PowerShell, mshta, rundll32, curl, WMI, and WebDAV for obfuscation and Living-off-the-Land (LotL) attacks. Microsoft points out that ClickFix and TerminalFix have emerged as high-frequency initial intrusion vectors, impacting thousands of enterprise and personal devices worldwide daily. Multiple threat actors use these tactics to spread malware such as Lumma Stealer, Xworm, AsyncRAT, and MintsLoader, which can further lead to credential theft, lateral movement, and ransomware attacks. The tech giant advises users against following prompts from CAPTCHAs, web error pages, emails, or ads to paste and execute any commands in Windows Run, Terminal, PowerShell, or Command Prompt.

2026.07.09 23:36

Security Warning: Abnormal on-chain fund flows detected for the CodexField project on BNB Chain.

On-chain investigator Specter has issued a community security alert, warning of potential fund misappropriation risks associated with the CodexField project on BNB Chain. On-chain tracking shows the project has amassed over $85 million in funds. Specter detected abnormal on-chain fund flows yesterday: a wallet bridged 17.3 million USDT from TRON to Ethereum, then swapped the tokens for DAI via Bitget Swap on Polygon. So far, $6.5 million has been transferred out, while the remaining $10.8 million is still in transit. The funds were originally bridged from Ethereum to TRON roughly six months ago, and the source wallet is linked to CodexField’s deposit contract. Below are key addresses for users to verify on their own: EVM: 0xBc606358910b3720d136F0d4Ce12b759C270747a TRON: TQNTEYadFVVQeobBtctSjurJ5RpfBsTmqh, TAzpg8L1WkkzCxxZk8TYnvaRYahehh52MK Related deposit contract: 0x9E6A75b546B65E7B9D34E2c9aB8Fe224B9aA52AA Additional red flags: The project requires a minimum $100 deposit for participation. Blockchain security tool Blocksec MetaSuites initially labeled the deposit contract as "Fake CodexField", but Specter’s follow-up investigation found the contract is actually operated by the CodexField team itself. The project uses multiple domains and subdomains to collect user deposits, and the team previously shared these domains via official channels. Its fund flow pattern is unusual, deviating from standard fund management practices: the project bridges funds across multiple blockchains, routes them through intermediate wallets, and ultimately sends assets to centralized exchanges. Specter noted that based on on-chain activity, the project warrants high vigilance. It advises all users interacting with CodexField to exercise extreme caution until the team provides a transparent explanation of its fund movements.

Page 1 / 13 Next →

Popular tokens

BitcoinEthereumHyperliquidSolanaTRONBNBTetherAaveXRPPepeFartcoinOndoJupiterUniswapBonkPendleEthenaArbitrumAvalancheLidoChainlinkPolygonDogecoinCardano