May 2025 - YDT Yellow Duck Token proxyTransfer Backdoor Exploited - $41k (Global)

YDT is short for "Yellow Duck Token". The smart contract was launched on May 24th.
"A simple bug (or possibly a backdoor?) in the proxyTransfer() function allows an attacker to transfer tokens from any address by passing in a privileged address."
TenArmor reports losses as $41.4k.
The incident was reported on by TenArmor. It is unclear if the project has any public face.
It is unclear if any funds have been recovered or any investigation is underway.
There is no suggestion that any funds have been recovered.
The incident appears to have faded to history. There's no indication that anything is still being investigated.
Further Analysis
The Yellow Duck Token (YDT), launched on May 24th, suffered a \$41.4k loss due to a vulnerability—or possible backdoor—in its `proxyTransfer()` function, which allowed an attacker to transfer tokens from any address using a privileged account; the incident was reported by TenArmor, and there is no evidence of fund recovery or an ongoing investigation.
How Could This Have Been Prevented?
More Cryptocurrency Exchange Hacks/Scams/Frauds
Ethereum ZeroTransfer Address Pollution Phishing Twice > > < < DAOSquare Treasury RICE Exploit Theft New Token Recovery
Sources/Further Reading
TenArmor - "Our system has detected a suspicious attack involving #YDT token on #BSC, resulting in an approximately loss of $41.4K. A simple bug (or possibly a backdoor?) in the proxyTransfer() function allows an attacker to transfer tokens from any address by passing in a privileged address." - Twitter/X (Dec 31)
Suspicious YDT Transaction - BSCScan (Dec 31)
Week 21, 2025 - BlockThreat (Dec 31)
YDT Token Smart Contract - BSCScan (Dec 31)
YDT Smart Contract Creation - BSCScan (Dec 31)
t.me/QuadrigaInitiative
|
/r/QuadrigaInitiative
|
@QuadrigaInit
|
info@quadrigainitiative.com
|
t.me/QuadrigaInitiative
/r/QuadrigaInitiative
@QuadrigaInit
info@quadrigainitiative.com