Bitcoin Mission
April 22, 2025
Unrestricted function access turned $1.3M into digital ash on Arbitrum.
FORENSIC REPORT
TIME OF DEATH: April 22, 2025, approximately 0400 UTC. The specimen—Bitcoin Mission protocol on Arbitrum—was discovered in critical condition following unauthorized function invocation. Preliminary field assessment indicated complete liquidity exsanguination. No signs of struggle. Death was mercifully swift.
CAUSE OF DEATH ANALYSIS: Examination reveals the overPaper function operated without proper permission gatekeeping. The attacker executed what can only be described as an open invitation to financial murder—the function accepted arbitrary external calls like a nightclub bouncer who'd given up on life. No access control modifiers, no caller validation, no pause mechanisms. The specimen's smart contract exhibited the digital equivalent of leaving the vault door propped open with a fire extinguisher. The exploit pathway was so straightforward that the coroner's intern could have executed it while reviewing TikTok.
CONTRIBUTING FACTORS: Standard autopsy findings show multiple warning signs the victim should have heeded. The codebase displayed textbook negligence: functions accessible to any entity with sufficient gas and malicious intent. No multi-signature requirements. No timelocks. No emergency pause functions worth mentioning. The victim's development team appears to have consulted the "How to Make Money for Hackers" playbook instead of following basic security hygiene. Arbitrum's permissive environment provided the perfect hunting ground for predators.
VICTIM IMPACT: $1.3 million transferred from the living to the criminal. Investors sustained catastrophic portfolio degradation. The protocol's reputation entered a state of necrotic decay from which recovery is anatomically improbable. Users who trusted this implementation now experience the spiritual sensation of watching their capital transform into someone else's Porsche down payment.
PATHOLOGIST'S NOTE: We're entering year eight of "move fast and break things," and the body count in DeFi continues its relentless climb. The overPaper function exploited here was essentially a loaded gun labeled "Free Money—Please Shoot Yourself." And shoot they did. The specimen presented all the defensive capabilities of a paper thin security model, which—in retrospect—was probably not coincidental branding. Another one for the wall.
"Bitcoin Mission flatlined after attackers exploited the overPaper function, draining $1.3M in cold blood. Another Arbitrum casualty. The body shows classic signs of insufficient access controls."
Data from DefiLlama