AES Hack
What happened
On 7 December 2022, the AES token on BNB Chain was exploited for about $61.6K. AES was a deflationary, fee-on-transfer token. BlockSec found that its transfer logic handled fees differently when tokens were sent to its PancakeSwap pair (0x40ed...07e3). The attacker abused this special case to push the pool's AES reserve down and sell back into it at a distorted price.
The attack ran in one transaction (0xca4d0d24...d0ae19) that flash-borrowed USDT from DODO and swapped 100,000 USDT for AES. BlockSec said this transaction came from a well-known MEV bot (0x286e09932b8d096cba3423d12965042736b8f850) that front-ran the original attack transaction, which fits PeckShield's note that the exploiter seems to have front-run another address (0x4054...671). PeckShield also reported that AES dropped about 89% afterwards.
How it happened
- The attacker flash-borrowed USDT from a DODO pool and swapped 100,000 USDT for AES through PancakeSwap.
- They sent half of their AES directly to the AES pair, then called the pair's
skim(pair)37 times. Each call moved the excess balance from the pair back to the pair itself, triggering the token's pair-specific fee handling on every transfer. BlockSec says this burned part of the pair's balance and increased the swap fee recorded in the AES contract. - They called
skimonce more to recover the excess AES, then called the token's publicdistributeFee(). According to BlockSec's analysis, this transferred the accumulated swap fee out of the pair directly. - They called
sync()so that the pair adopted the reduced AES balance as its reserve, which made AES expensive relative to USDT. - They sold their AES for USDT at the manipulated price, repaid the DODO flash loan, and kept about 61.6K USDT profit.
Protocol details
Evidence
- report BlockSec alert thread on the AES attack (X, via fxtwitter mirror) twitter.com
- report PeckShield alert: AES exploited (~61.6k) (X, via fxtwitter mirror) twitter.com
- report BlockSec thread tweets 2/-4/ on the AES attack (X, via fxtwitter thread mirror) twitter.com
- analysis DeFiLlama defillama.com
- analysis DeFiHackLabs AES_exp.sol PoC raw.githubusercontent.com
- analysis EvoPoC: Automated Exploit Synthesis for DeFi Smart Contracts via Hierarchical Knowledge Graphs (Table III) arxiv.org
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.