Share this article

How Attackers Made $15M From Staking Platform Helio After Ankr Exploit

A delay in updating price data on BNB-related derivative tokens allowed some exploiters to piggyback off a previous attack.

Updated Dec 2, 2022, 3:39 p.m. Published Dec 2, 2022, 1:25 p.m.
(Adam Levine/CoinDesk)
(Adam Levine/CoinDesk)

An unknown group of attackers were able to drain some $15 million in liquidity from BNB Chain-based staking platform Helio on Friday morning after exploiting an oracle issue on the protocol, on-chain data shows.

HAY's staking pools continue to hold some $19 million in liquidity. (Helio)
HAY's staking pools continue to hold some $19 million in liquidity. (Helio)
STORY CONTINUES BELOW
Don't miss another story.Subscribe to the The Protocol Newsletter today. See all newsletters

Oracles are third-party services that fetch data from outside sources to within a certain blockchain. Oracles are extensively used by decentralized finance (DeFi) protocols to ensure their lending, borrowing and other services are accurate. Delays, however, could mean the loss of funds as malicious traders take advantage of price differences.

The Helio exploit came hours after the DeFi Ankr was attacked for $5 million. The Ankr attacker was able to mint 6 quadrillion aBNBc tokens, which they eventually turned into roughly 5 million USDC, as CoinDesk reported.

The Ankr exploit caused the prices of aBNBc tokens to plunge 99% in the minutes following the attack, setting the base for the second exploit on Helio. It is unclear at writing time if both the attacks were conducted by the same attacker or group of attackers.

Blockchain data shows that the Helio attacker acquired some 183,000 aBNBc tokens with 10 BNB during Asian morning hours on Friday. Delayed oracle data on Helio then allowed the attacker to borrow $16 million worth of HAY stablecoin.

The illicitly gained HAY was then swapped for 15 million Binance USD (BUSD), blockchain data cited by security firms BlockSec and PeckShield shows.

The HAY staking pool continues to hold some $19 million in locked funds, with developers stating in European afternoon hours that staked funds remained safe. Helio said in a separate tweet that it was working to mitigate the ongoing situation and asked users to avoid transacting in HAY.

Meanwhile, Binance froze some $3 million linked to the attack that were allegedly moved by the attackers to the exchange, founder Changpeng Zhao said in a Friday tweet.

Read more: DeFi Protocol Ankr to Reimburse Users Affected by $5M Exploit

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

Most Influential: Rushi Manche

Rushi Manche

The Movement Labs’ co-founder’s secret dealings and subsequent scandal stoked industry-wide anxieties about opaque token allocations and insider trading.