QI Quadriga Initiative

May 2025 - YDT Yellow Duck Token proxyTransfer Backdoor Exploited - $41k (Global)

YDT is short for "Yellow Duck Token". The smart contract was launched on May 24th.

"A simple bug (or possibly a backdoor?) in the proxyTransfer() function allows an attacker to transfer tokens from any address by passing in a privileged address."

TenArmor reports losses as $41.4k.

The incident was reported on by TenArmor. It is unclear if the project has any public face.

It is unclear if any funds have been recovered or any investigation is underway.

There is no suggestion that any funds have been recovered.

The incident appears to have faded to history. There's no indication that anything is still being investigated.

Further Analysis

The Yellow Duck Token (YDT), launched on May 24th, suffered a \$41.4k loss due to a vulnerability—or possible backdoor—in its `proxyTransfer()` function, which allowed an attacker to transfer tokens from any address using a privileged account; the incident was reported by TenArmor, and there is no evidence of fund recovery or an ongoing investigation.

How Could This Have Been Prevented?

More Cryptocurrency Exchange Hacks/Scams/Frauds

Ethereum ZeroTransfer Address Pollution Phishing Twice > > < < DAOSquare Treasury RICE Exploit Theft New Token Recovery

Sources/Further Reading

TenArmor - "Our system has detected a suspicious attack involving #YDT token on #BSC, resulting in an approximately loss of $41.4K. A simple bug (or possibly a backdoor?) in the proxyTransfer() function allows an attacker to transfer tokens from any address by passing in a privileged address." - Twitter/X (Dec 31)
Suspicious YDT Transaction - BSCScan (Dec 31)
Week 21, 2025 - BlockThreat (Dec 31)
YDT Token Smart Contract - BSCScan (Dec 31)
YDT Smart Contract Creation - BSCScan (Dec 31)


Join Us!

Name: Email:

t.me/QuadrigaInitiative /r/QuadrigaInitiative @QuadrigaInit info@quadrigainitiative.com

Sign-Ups: 100%

Your use of this site/service accepts the Terms of Use and Privacy Policy. This site is not associated with Ernst & Young, Miller Thompson, or the Official Committee of Affected User. For questions or enquiries, email info@quadrigainitiative.com.