Ankr disclosed on December 2, 2022, that an attacker had compromised a developer key and altered the smart contract governing aBNBc, one of its BNB liquid-staking tokens. The company estimated that approximately $5 million worth of BNB had been removed from liquidity pools across decentralized exchanges.
BNB Chain records place exploit-associated activity shortly after 00:43 UTC on December 2. Ankr’s report referred to the incident as a December 1 hack, creating an apparent date difference attributable to reporting convention or timezone. Its eligibility snapshot was explicitly fixed at 00:43:18 UTC on December 2, at block 23,545,403. This reconstruction therefore uses December 2, the UTC date recorded by the chain and the date of Ankr’s public incident report.
The event mattered beyond its immediate loss estimate. The attacker did not need to defeat BNB Chain’s consensus or compromise the BNB held by validators. Instead, access to a privileged deployment key allowed the attacker to replace contract logic and manufacture tokens that decentralized-finance applications had treated as claims on staked BNB.
An unauthorized mint met real liquidity
Ankr described aBNBc as a reward-bearing representation of staked BNB. According to its same-day report, the altered contract permitted minting without the expected authorization checks. The exploit-associated address then created 60 trillion aBNBc across six transactions and exchanged part of that supply through decentralized exchanges.
The newly minted tokens had no corresponding increase in underlying staked BNB. Nevertheless, automated liquidity pools initially accepted them according to their programmed trading rules. That let the attacker exchange artificial supply for assets with independent value until liquidity was depleted or trading routes were interrupted.
The distinction is important: 60 trillion was the quantity Ankr said was minted, not the attacker’s dollar profit. Ankr’s approximately $5 million figure was its preliminary estimate of BNB losses across affected liquidity pools. It was not an audited calculation, and the company did not publish a complete transaction-by-transaction reconciliation on December 2.
Contemporaneous Reuters reporting said Binance paused withdrawals involving Ankr-related tokens and froze approximately $3 million that had reached the centralized exchange. That amount was attributed to Binance’s chief executive and should not be treated as proof that all remaining proceeds were identified, recoverable or controlled by a single actor.
Ankr retired the affected token design
Ankr said it alerted trading venues, secured the contracts with a new key and temporarily paused movement of underlying collateral. It also announced that aBNBc and aBNBb would be discontinued and replaced with a new ankrBNB token distributed according to the pre-exploit snapshot.
The company committed to purchasing $5 million of BNB to compensate affected liquidity providers. That was a contemporaneous recovery commitment, not evidence on December 2 that every claim had been validated or paid. Ankr separately said underlying staked assets, validators, remote-procedure-call services and AppChain infrastructure were unaffected; those statements came from the operator and were not an independent audit of every system.
Why privileged access was the central risk
The incident illustrated how a token described as decentralized could still depend on centralized administrative credentials. Users and connected protocols faced not only ordinary smart-contract bugs but also the possibility that an authorized upgrade mechanism could be turned against them if its controlling key was compromised.
It also demonstrated composability risk. Once a compromised token entered exchanges, liquidity pools and collateral systems, losses could spread beyond the contract where the unauthorized mint began. The durable event-day conclusion was therefore narrower than any final forensic judgment: on December 2, the chain record and Ankr’s disclosure established an unauthorized mint, disrupted liquidity and an emergency token replacement, while the attacker’s identity and complete downstream loss remained unresolved.
Later context
Ankr stated in a December 20 after-action report that a former team member had conducted a social-engineering and supply-chain attack that compromised the private key. That later attribution was the company’s finding, not something established in the December 2 record, and it is not projected backward as an event-day certainty.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

