shield Access Control · $400K loss

How PLN lost $400K to an access control in September 2024

On September 2024, PLN was exploited in a access control, resulting in approximately $400K in losses. That makes the PLN exploit the 130th largest DeFi incident out of 690 documented in our archive.

Attack Mechanics: How the PLN Access Control Played Out

Exploit Class Applied to PLN

The PLN incident on September 5, 2024 is classified as a Access Control. A privileged function lacks a proper authorisation check, letting an unauthorised caller execute it. In the full archive, PLN is 1 of 77 documented access control incidents.

PLN in Context

At $400K, the PLN exploit is a minor (<$1M) event compared to the largest same-class incident in our archive — Corkprotocol (2025) at $12M.

Prior Access Control Before PLN

The nearest access control incident before PLN was Unverified_16d0, 1 day earlier on September 4, 2024 ($329 lost). The same exploit class surfaced again within the access control attack surface.

Impact & Recovery for PLN

PLN Loss Figure

The PLN exploit caused $400,000 in losses — a minor (<$1M) incident and the 33rd largest of 188 documented in 2024. This single incident represents 0.1% of all tracked losses that year.

Where PLN Sits Among Access Control Attacks

Ranked by loss size, PLN is the 10th largest of 77 access control incidents documented. That puts the PLN loss below the class average of $636K.

Timeline Since the PLN Incident

The PLN exploit occurred 1.6 years ago (586 days). The contract, its fork-block, and the attack transaction remain on-chain and forensically reproducible.

Primary Reference for PLN

Public post-mortem / on-chain analysis for the PLN incident: view source.

FAQ

How much did PLN lose?

The PLN exploit in September 2024 resulted in $400,000 in losses — the 33rd largest of 188 DeFi incidents that year.

When did the PLN hack happen?

The PLN exploit was recorded on September 5, 2024 — 586 days ago.

What type of exploit hit PLN?

The PLN incident is classified as a Access Control. A privileged function lacks a proper authorisation check, letting an unauthorised caller execute it.

How common is the Access Control pattern seen at PLN?

Our archive contains 77 documented access control incidents. The PLN incident is one of them.

How does PLN compare to the largest Access Control attack?

The largest access control incident in our archive is Corkprotocol (2025) at $12M. The PLN loss is $400K.

How does blockchain technology potentially solve e-commerce security challenges?

Blockchain simplifies fraud detection and investigation by recording detailed and immutable transaction data.

What challenge does the protocol aim to address regarding multi-party transactions across blockchains?

It aims to enable secure and private multi-party transactions without the need for a trusted third party or revealing transaction details to the network.