OceanAltOceanAlt

Security incident · 2025-02-21

StepHeroNFTs

According to the public DefiLlama incident dataset, StepHeroNFTs (BSC) suffered a security incident on 2025-02-21, with about $90K reported lost.

Date2025-02-21
Reported loss$90K
ChainBSC
Target typeDeFi Protocol
Technique classReentrancy
TechniqueReentrancy
Bridge incidentNo
Within 2025#122 by loss that year, 0.0% of all reported losses that year

How this kind of attack works

The contract sent funds before updating balances, and the attacker re-entered during the transfer to withdraw repeatedly.

Would a pre-payment check have helped

Needs other controls

Reentrancy is a classic contract bug, unrelated to the counterparty; code audits address it.

Other incidents with the same technique

Sources

This page restates public reports and is not OceanAlt's judgment of any party. To report an error, email business@oceanalt.com; we review within 48 hours.

← Back to incidents