Amnext Hack
What happened
On September 9, 2026, PoolTogether-V3 fork Amnext (AMC) on BNB Smart Chain was exploited for ~$116.1K USD (~154 WBNB) after a credit-burn accounting flaw allowed an attacker to repeatedly re-claim prize allocations, inflate their ticket balance, and liquidate the underlying tokens on PancakeSwap.
Following a Chainlink VRF draw resolution (requestId 1108) where the attacker won an external NFT prize, the attacker exploited a broken credit-consumption check in the PrizePool contract's award path. During prize claiming, the system failed to reduce the user's credit balance (CreditBurned remained at 0 across iterations). The attacker looped this execution ~20 times within a single transaction, re-awarding the same credit repeatedly to mint ~376.5M unearned ticket tokens.
The attacker then executed an InstantWithdrawal, paid a ~1.2% early exit fee (~4.6M tickets), redeemed ~372M underlying AMC tokens, and dumped the full supply on PancakeSwap V2 for ~154 WBNB before unwrapping to native BNB.
Attack Transactions:
Main Exploit: 0x29eb9725…08afc5
Liquidation: 0x99c9969a…85d3ba
Case & protocol details
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report x.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.