383 hack event(s)
Description of the event: The old BNB Chain DeFi protocol Amnext (AMC), a no-loss lottery/prize-pool product, was exploited. The attacker mass-minted Ticket AMC and drained about 154.02 WBNB from the protocol via PancakeSwap, causing a loss of approximately $ 116,100.
Amount of loss: $ 116,100 Attack method: Smart Contract Vulnerability
Description of the event: The WealthManagementV2 contract lost funds after owner privileges were suspected of being illegally transferred (possibly due to a leaked private key). The attacker-controlled owner instantly set extreme plan parameters (period=0, interestMultiplier/unlockMultiplier=528,300,000) via updatePlanConfig with no timelock or bounds, minted inflated interest by investing and redeeming in the same transaction, then unlocked and withdrew the funds via a second investment, resulting in a loss of 26,414 USDT.
Amount of loss: $ 26,414 Attack method: Private Key Leakage
Description of the event: An unnamed DEX router on BNB Chain was exploited because uniswapV3SwapCallback did not authenticate a real V3 pool. The attacker used a fake pool, set victims as payer, and drained existing token allowances via transferFrom, stealing about 62.28 WBNB from 29 wallets in one transaction.
Amount of loss: $ 46,070 Attack method: Smart Contract Vulnerability
Description of the event: Dream Health Chain’s staking/reward contracts on BSC were exploited for about 71,851 USDT. A broken award state machine allowed a claimed reward to be reset with a tiny or zero-effective DHC deposit, so the same fixed payout could be claimed repeatedly from the shared pool. The attacker looped pledge and claim, then sold about 542,070 DHC into the DHC-USDT pool.
Amount of loss: $ 71,851 Attack method: Smart Contract Vulnerability
Description of the event: CashCowCoin’s unverified trading router implementation contract had a flawed sell() flow. After the PancakeSwap Router completed the CCC→WBNB swap, the proxy called a privileged token function to transfer post-tax CCC from the Pair to the dead address and invoked Pair.sync(). This burned the sell-side CCC while permanently retaining the reduced WBNB reserve, enabling repeated draining of the pool’s WBNB through about 80 iterative sell cycles.
Amount of loss: $ 117,400 Attack method: Smart Contract Vulnerability
Description of the event: FH Token on the BSC chain was exploited in its FH/USDT liquidity pool on PancakeSwap V2. A flaw in the token’s _transfer function and isSell logic caused incorrect token burns during sells, allowing the attacker to drain funds from the pool through repeated buy-and-sell loops, resulting in a loss of approximately $20,000.
Amount of loss: $ 20,000 Attack method: Smart Contract Vulnerability
Description of the event: FoxMarket (a DeFi project on BSC) had its FoxLpBondsPool.stake() function calculate and fix _stakeAmount from a manipulable Pancake AMM spot quote before a large USDT→Fox swap. The attacker used flash loans to skew pair reserves, then addLiquidity used a mismatched ratio; Treasury.lpBonds() trusted the stale value, minted excess Fox tokens, and sent inviter rewards to an attacker-controlled address, which were sold in the same transaction.
Amount of loss: $ 118,700 Attack method: Flash Loan Attack
Description of the event: LOOPSDAO’s LpdFi protocol on BSC was exploited. The attacker used a flash loan to manipulate the spot price of the thin PancakeSwap LPD/USDC pair (no TWAP or deviation guard), opened a massively inflated interest-bearing position with minimal LPD, and claimed interest right across the daily settlement boundary. This triggered the protocol to burn its own Cake-LP and pay out the inflated amount, draining approximately $690,000.
Amount of loss: $ 690000 Attack method: Price Manipulation
Description of the event: The MOKE token protocol on BNB Chain was exploited via a smart contract vulnerability. The attacker abused an unprotected public claim() function in MokeToken.releaseContract() (no eligibility check on the caller), repeatedly draining ~166 million MOKE from the protocol’s internal reserve pool, then used flash loans, Venus leverage, LP removal, and dividend distribution mechanisms to convert it into ~1,546 BNB, resulting in a loss of approximately $907,700.
Amount of loss: $ 907700 Attack method: Smart Contract Vulnerability
Description of the event: The decentralized asset management protocol Swan Treasury on BNB Chain was exploited due to the leakage of an off-chain signer's private key (the _signer key hardcoded in the ZhaiquanBuy contract). The attacker forged valid signatures and used PancakeSwap flash loans to purchase approximately 687,000 STY tokens at around a 100x discount (spending approximately 19,700 USDT). The attacker then forged the related claim()/transfer signatures and dumped the tokens into the STY/USDT pool, making a profit of approximately $625,000.
Amount of loss: $ 625,000 Attack method: Private Key Leakage
Description of the event: The Pro token contract of Crypto DAO was exploited due to missing access control, with the attacker calling publicly accessible vault functions. According to GoPlus Security’s analysis, the attacker’s actual profit was approximately $52,000, while the contract lost around 167,200 Pro tokens. The related addresses monitored by Blockaid collectively held approximately $8.2 million worth of USDT (not the actual stolen amount).
Amount of loss: $ 52,000 Attack method: Smart Contract Vulnerability
Description of the event: The LULA token on BSC was exploited when attackers abused the privileged recycle() function in its contract, combined with an approximately $237 million flash loan to manipulate PancakeSwap V2 liquidity pool reserves, resulting in a loss of about $578,100.
Amount of loss: $ 578,100 Attack method: Price Manipulation Attack
Description of the event: The 42DAO protocol was exploited. The attacker manipulated the Median Oracle with an abnormally low BTCB price, triggering forced liquidations of multiple BTCB vaults and profiting approximately $915,000. This caused its algorithmic stablecoin Balance Coin (BLC) to crash over 99% from near $1 to about $0.001.
Amount of loss: $ 915,000 Attack method: Price Oracle Manipulation
Description of the event: AIDC token on BSC was exploited due to a flaw in _sellTransfer()/burn logic. The attacker manipulated the PancakeSwap LP pool, causing burn fees to accumulate without properly deducting from sender balance, draining ~$121K WBNB.
Amount of loss: $ 121,000 Attack method: Smart Contract Vulnerability
Description of the event: The OLPC/LABUBU liquidity pool on PancakeSwap V2 (BNB Chain) was exploited, resulting in approximately $1.1 million in losses. The attacker exploited a logic vulnerability in the OLPC token contract’s _update function. Approximately 46 days prior, the OLPC owner had maliciously changed the decimalsValue parameter to an extremely large value (7326680472586200649) and later renounced ownership. A small OLPC transfer triggered massive burns of OLPC and LABUBU tokens from the pool (to the dead address), desynchronizing the pair’s cached reserves. This allowed the attacker to drain a large amount of LABUBU, which was swapped through intermediate pools for ~1.115 million USDT. Funds were bridged to Ethereum and deposited into Tornado Cash.
Amount of loss: $ 1,100,000 Attack method: Smart Contract Vulnerability
Description of the event: The JB DeFi protocol suffered an exploit involving flashloan and price manipulation, resulting in approximately $50,000 being drained. The attack exploited protocol logic through flash loan-enabled price manipulation on the Solidity-based contract.
Amount of loss: $ 50,000 Attack method: Flash Loan Price Manipulation
Description of the event: On June 17, 2026, Little Boy Plus — a fully decentralized DeFi mining protocol on BSC claiming “no team, no admin keys” — was exploited. An attacker exploited a logic vulnerability in the LBPHashrate contract’s _update() function. By triggering it with a zero-value transferFrom call (bypassing OpenZeppelin authorization), the attacker unauthorizedly called _harvest and minted LBP tokens directly to the PancakeSwap LBP/USDT pair via mintReward. This inflated the pair’s balance without updating reserves, allowing the attacker to drain ~377,642 USDT (~$367k–$378k) through PancakePair.swap(). The funds were later sent to Tornado Cash.
Amount of loss: $ 367,000 Attack method: Smart Contract Vulnerability
Description of the event: The DIP token contract (Etherisc ecosystem) was exploited due to a missing return statement in the _transfer() function for PancakeSwap-routed trades, causing double transfers. The attacker used skim(router) and sync() to manipulate the pool and drain ~$111K USDC.
Amount of loss: $ 111,000 Attack method: Smart Contract Vulnerability
Description of the event: The DTXT/USDT liquidity pair on BSC was exploited. The attacker exploited a forgeable liquidity-addition detection logic in the DTXT contract (by sending a small amount of USDT directly to the pair address, tricking the contract into classifying large sells as liquidity additions). This bypassed sell fees and drained the pool, resulting in a loss of approximately $35,041 USDT.
Amount of loss: $ 35,041 Attack method: Business Logic Vulnerability
Description of the event: The ATM token on BSC was exploited due to a flaw in its custom transferFrom() function logic (which automatically swapped ~20% of transferred amounts to BSC-USD). The attacker repeatedly triggered the mechanism to drain approximately $243,500 from the protocol.
Amount of loss: $ 243,500 Attack method: Smart Contract Vulnerability