Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
GANA Payment Exploited for $3.1M, Hacker Laundered via Tornado

GANA Payment Exploited for $3.1M, Hacker Laundered via Tornado

coinfomaniacoinfomania2025/11/20 14:39
By:coinfomania

Quick Take Summary is AI generated, newsroom reviewed. GANA Payment was hit by an exploit resulting in the theft of over $3.1 million from its contracts. The hacker quickly laundered $1,140 BNB and $346.8 ETH through Tornado Cash on both BNB Chain and Ethereum. An additional $346 ETH ($1.04M) remains in the attacker's Ethereum wallet, currently unlaundered. The clean execution highlights the speed with which attackers can disperse funds across multiple chains, complicating recovery efforts.References accor

GANA Payment, a payments focused crypto project operating on the BNB Chain. It has been hit by a major exploit. That drained more than $3.1 million from its contracts. The attack is flagged by blockchain investigator ZachXBT. It is the latest reminder of how quickly funds can disappear across chains. When vulnerabilities meet determined attackers.

Hacker Moves Fast With Stolen Funds

The GANA Payment exploit occurred within hours. The attacker wasted no time dispersing the stolen assets. According to ZachXBT’s on-chain analysis, the attacker first consolidated the stolen funds into a single address. Then began the laundering process. The attacker deposited 1,140 BNB worth roughly $1.04 million into Tornado Cash on the BNB Chain. 

吴说获悉,据 ZachXBT 监测,GANA Payment 在 BNB Chain 遭攻击,损失金额超过 310 万美元。攻击者已将 1140 枚 BNB(约 104 万美元)通过 Tornado Cash 混币,并将部分资金跨链至以太坊网络:其中 346.8 枚 ETH(约 105 万美元)已存入以太坊端的 Tornado Cash,约 346 枚 ETH(约 104.6…

Tornado Cash is a popular crypto mixer. It is often used to obscure transaction trails by blending deposited assets with large liquidity pools. This step made the stolen funds significantly harder to track. Next, the attacker bridged a portion of the funds to Ethereum. Once on Ethereum , they deposited 346.8 ETH around $1.05 million into Tornado Cash again. Continuing the laundering strategy across chains. Despite this activity, an additional 346 ETH is valued at roughly $1.046 million. Currently sits untouched in the attacker’s Ethereum wallet.

On-Chain Details Reveal a Clean Execution

Transaction logs on BscScan show seven outgoing transactions from the primary attacker address. These movements include multiple transfers of BUSD-T and small amounts of BNB. With fees so low they barely registered. The address now holds less than 0.01 BNB, essentially drained after distributing or mixing the stolen funds. On Ethereum, the GANA Payment attacker’s wallet holds more than 346 ETH. The address shows only one major interaction since receiving the bridged funds. 

An approval transaction for USDT. No major outflows have occurred yet. This suggests the attacker may be waiting for the right moment to move the remaining balance. These findings highlight how quickly attackers adapt and spread stolen assets across multiple networks. Each bridge, approval and mixer deposit makes it harder and harder for investigators to freeze or recover funds.

Community Reacts as Security Questions Rise

For many users, the GANA Payment exploit reinforces ongoing fears about protocol security. Especially for smaller or less established projects. While major chains like BNB Chain and Ethereum offer strong infrastructure. The vulnerabilities within individual projects can lead to massive losses. Security analysts have urged GANA Payment to release a detailed post-mortem as soon as possible. They also recommend halting any affected contracts, notifying users and coordinating with exchanges to flag suspicious wallet activity.

What Happens Next?

Currently, the attacker still controls more than a million dollars in unlaundered ETH. Whether that amount moves next, or simply sits dormant, remains unclear. Recovery appears unlikely, but investigators continue to monitor the attacker’s wallets for new activity. For the broader crypto community, the GANA Payment exploit is yet another push to prioritize real security audits and smarter contract design. In a space where money moves fast, prevention remains the only real defense.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

XRP News Today: The Crypto World’s Delicate Balance Between Progress and Volatility

- CoinMarketCap and Reserve launch CMC20, a DeFi-native index token tracking top 20 cryptos on BNB Chain, blending blockchain transparency with diversified institutional-grade access. - Trump's WLFI crypto project suffers $2.85B value drop due to phishing attacks and poor key storage, exposing security risks in high-profile consumer-facing crypto ventures. - CredShields and Checkmarx partner to combat smart contract flaws via AI audits and enterprise security frameworks, addressing 48% of major DeFi breach

Bitget-RWA2025/11/20 18:54
XRP News Today: The Crypto World’s Delicate Balance Between Progress and Volatility

Demanding Responsibility: Titus Challenges Nevada Governor Regarding Withdrawn Penalties for The Boring Company

- Rep. Dina Titus demanded transparency after Nevada rescinded $425,595 in fines against Elon Musk's Boring Company for safety and environmental violations. - The fines, initially issued for incidents including firefighter chemical burns and alleged wastewater dumping, were revoked days after company contact with Lombardo's office. - Titus requested public hearings and document releases, citing internal records showing altered public records and procedural inconsistencies in the rescission. - State officia

Bitget-RWA2025/11/20 18:54
Demanding Responsibility: Titus Challenges Nevada Governor Regarding Withdrawn Penalties for The Boring Company

"Is It Possible for AI to Eliminate the Need to Work? Musk's Perspective Sparks Debate Among Specialists"

- Elon Musk predicts AI and robotics could make work optional within 10-20 years, eliminating money, as discussed at the U.S.-Saudi Investment Forum. - Experts question feasibility, citing high costs of physical automation and historical trends showing diminishing returns in tech adoption. - Skeptics highlight risks of growing inequality, noting AI gains disproportionately benefit tech giants while broader markets struggle. - Philosophical challenges include societal erosion from work displacement, with Mu

Bitget-RWA2025/11/20 18:54
"Is It Possible for AI to Eliminate the Need to Work? Musk's Perspective Sparks Debate Among Specialists"

Solana News Update: Amidst Crypto Market Fluctuations, Investors Turn to Solana ETFs for Regulated Access

- Solana (SOL) surged past $140 amid $2B inflows into spot ETFs, driven by VanEck’s launch and 17-day consecutive inflow streak. - The token benefits from capital shifting away from volatile memecoins, though regulatory scrutiny over transparency and wallet controls persists. - Bitcoin and Ethereum ETFs face $3B+ outflows in November, contrasting Solana’s institutional adoption and appeal as a regulated liquidity vehicle. - Analysts highlight Solana’s strategic role in a rising-rate environment, with co-fo

Bitget-RWA2025/11/20 18:54
Solana News Update: Amidst Crypto Market Fluctuations, Investors Turn to Solana ETFs for Regulated Access