{"id":59720,"date":"2025-11-21T14:01:34","date_gmt":"2025-11-21T14:01:34","guid":{"rendered":"https:\/\/dogewisperer.com\/?p=59720"},"modified":"2025-11-21T14:01:34","modified_gmt":"2025-11-21T14:01:34","slug":"3-1-million-vanishes-the-gana-payment-attack-no-one-saw-coming","status":"publish","type":"post","link":"https:\/\/dogewisperer.com\/?p=59720","title":{"rendered":"$3.1 Million Vanishes: The GANA Payment Attack No One Saw Coming"},"content":{"rendered":"<div>\n<p>GANA Payment, a project on <a href=\"https:\/\/www.bnbchain.org\/en\" target=\"_blank\" rel=\"noopener nofollow\">BNB Smart Chain<\/a>, lost more than $3.1 million after an attacker gained control of key contract rights, reports have disclosed.<\/p>\n<p>The thief moved much of the haul through <a href=\"https:\/\/tornado.cash\/\" target=\"_blank\" rel=\"noopener nofollow\">Tornado Cash<\/a> on both BSC and <a href=\"https:\/\/www.coingecko.com\/en\/coins\/ethereum\" target=\"_blank\" rel=\"noopener nofollow\">Ethereum<\/a>, while roughly $1 million remains idle on Ethereum addresses.<\/p>\n<h2>How The Attack Unfolded<\/h2>\n<p>According to posts by blockchain researcher ZachXBT, the exploiter consolidated stolen assets at address 0x2e8***5c38 before sending 1,140 BNB \u2014 about $1.04 million \u2014 into Tornado Cash on BSC.<\/p>\n<p><img data-recalc-dims=\"1\" fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter size-full wp-image-631777\" src=\"https:\/\/bitcoinist.com\/wp-content\/uploads\/2025\/11\/A_0430d7.png?resize=542%2C853\" alt=\"\" width=\"542\" height=\"853\" srcset=\"https:\/\/bitcoinist.com\/wp-content\/uploads\/2025\/11\/A_0430d7.png?w=542 542w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2025\/11\/A_0430d7.png?w=267 267w, https:\/\/bitcoinist.com\/wp-content\/uploads\/2025\/11\/A_0430d7.png?w=419 419w\" sizes=\"(max-width: 542px) 100vw, 542px\"><\/p>\n<p>The thief then bridged funds to Ethereum and pushed 346.8 ETH valued at approximately $1.05 million through the same mixer.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\">According to Zach (<a href=\"https:\/\/twitter.com\/zachxbt?ref_src=twsrc%5Etfw\" rel=\"nofollow noopener\" target=\"_blank\">@zachxbt<\/a>), the GANA Payment\u2019 project was exploited for over $3.1M on BSC earlier today.<\/p>\n<p>The attacker first sent 1,140 <a href=\"https:\/\/twitter.com\/search?q=%24BNB&amp;src=ctag&amp;ref_src=twsrc%5Etfw\" rel=\"nofollow noopener\" target=\"_blank\">$BNB<\/a> ($1.04M) into Tornado Cash on BSC, then bridged the stolen funds to <a href=\"https:\/\/twitter.com\/hashtag\/Ethereum?src=hash&amp;ref_src=twsrc%5Etfw\" rel=\"nofollow noopener\" target=\"_blank\">#Ethereum<\/a> and deposited another 346 <a href=\"https:\/\/twitter.com\/search?q=%24ETH&amp;src=ctag&amp;ref_src=twsrc%5Etfw\" rel=\"nofollow noopener\" target=\"_blank\">$ETH<\/a> ($1.05M) into Tornado.<\/p>\n<p>The\u2026 <a href=\"https:\/\/t.co\/q7DL8Mdpzf\" rel=\"nofollow\">pic.twitter.com\/q7DL8Mdpzf<\/a><\/p>\n<p>\u2014 Onchain Lens (@OnchainLens) <a href=\"https:\/\/twitter.com\/OnchainLens\/status\/1991407035473359283?ref_src=twsrc%5Etfw\" rel=\"nofollow noopener\" target=\"_blank\">November 20, 2025<\/a><\/p>\n<\/blockquote>\n<p>About 346 ETH, close to $1.05 million at the time, sits untouched at address 0x7a503***b3cca. Based on reports from security firm HashDit, the breach began when ownership of a <a href=\"https:\/\/gana-pay.com\/\" target=\"_blank\" rel=\"noopener nofollow\">GANA<\/a> contract was changed without permission, giving the attacker admin-level control over staking logic.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\">GANA Urgent Announcement<\/p>\n<p>GANA\u2019s interaction contract has been targeted by an external attack, resulting in unauthorized asset theft. Our technical team, together with an independent third-party security firm, has initiated an emergency investigation to analyze the attack vector,\u2026<\/p>\n<p>\u2014 GANA Payment (@GANA_PayFi) <a href=\"https:\/\/twitter.com\/GANA_PayFi\/status\/1991424973190361394?ref_src=twsrc%5Etfw\" rel=\"nofollow noopener\" target=\"_blank\">November 20, 2025<\/a><\/p>\n<\/blockquote>\n<p>HashDit\u2019s analysis shows that whoever took control could call unstake routines and force the system to release far more GANA tokens than it should have.<\/p>\n<p>Those excess tokens were quickly sold off for more liquid assets and then routed into privacy tools. This is a familiar script: manipulate permissions, mint or extract tokens, convert into stable or liquid crypto, then launder.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full\" src=\"https:\/\/www.tradingview.com\/x\/R2kUl4yW\/\" width=\"2048\" height=\"985\"><\/p>\n<h2>Who Spotted It And What Happened Next<\/h2>\n<p>ZachXBT flagged the suspicious moves on his Telegram channel. HashDit then dug into the contract and identified the altered ownership as the trigger.<\/p>\n<p>GANA\u2019s team posted an emergency notice acknowledging unauthorized activity on their interaction contract and said they brought in an outside security firm to investigate.<\/p>\n<p>The project said it will map user addresses and permissions as part of a planned reboot and will publish recovery steps and timelines through official channels.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\"><img decoding=\"async\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/16.0.1\/72x72\/1f6a8.png\" alt=\"\ud83d\udea8\" class=\"wp-smiley\" style=\"height: 1em; max-height: 1em;\">HashDit Alert<img decoding=\"async\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/16.0.1\/72x72\/1f6a8.png\" alt=\"\ud83d\udea8\" class=\"wp-smiley\" style=\"height: 1em; max-height: 1em;\"><\/p>\n<p>HashDit has monitored that <a href=\"https:\/\/twitter.com\/GANA_PayFi?ref_src=twsrc%5Etfw\" rel=\"nofollow noopener\" target=\"_blank\">@GANA_PayFi<\/a> has been compromised for ~$3.1m <a href=\"https:\/\/twitter.com\/search?q=%24GANA&amp;src=ctag&amp;ref_src=twsrc%5Etfw\" rel=\"nofollow noopener\" target=\"_blank\">$GANA<\/a>.<\/p>\n<p>Users should NOT trade with the <a href=\"https:\/\/twitter.com\/search?q=%24GANA&amp;src=ctag&amp;ref_src=twsrc%5Etfw\" rel=\"nofollow noopener\" target=\"_blank\">$GANA<\/a> token for the time being, and await for team announcement!<\/p>\n<p>Funds have been deposited into TC: <a href=\"https:\/\/t.co\/rtdjnMvYpI\" rel=\"nofollow\">https:\/\/t.co\/rtdjnMvYpI<\/a><\/p>\n<p>Root cause: Ownership of\u2026 <a href=\"https:\/\/t.co\/XZzuoMmf8D\" rel=\"nofollow\">pic.twitter.com\/XZzuoMmf8D<\/a><\/p>\n<p>\u2014 HashDit | now with Pro Extension (@HashDit) <a href=\"https:\/\/twitter.com\/HashDit\/status\/1991419082609160667?ref_src=twsrc%5Etfw\" rel=\"nofollow noopener\" target=\"_blank\">November 20, 2025<\/a><\/p>\n<\/blockquote>\n<p><em>Featured image from Pexels, chart from TradingView<\/em><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>GANA Payment, a project on BNB Smart Chain, lost more than $3.1 million after an attacker gained control of key contract rights, reports have disclosed. The thief moved much of the haul through Tornado Cash on both BSC and Ethereum, while roughly $1 million remains idle on Ethereum addresses. How The Attack Unfolded According to [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"iawp_total_views":0,"footnotes":""},"categories":[2],"tags":[3,4,5],"class_list":["post-59720","post","type-post","status-publish","format-standard","hentry","category-news","tag-crypto","tag-doge","tag-news"],"_links":{"self":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/59720","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=59720"}],"version-history":[{"count":0,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/59720\/revisions"}],"wp:attachment":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=59720"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=59720"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=59720"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}