Amnext Hack

REPORTED LOSS $116K
Low Reentrancy

What happened

On September 9, 2026, PoolTogether-V3 fork Amnext (AMC) on BNB Smart Chain was exploited for ~$116.1K USD (~154 WBNB) after a credit-burn accounting flaw allowed an attacker to repeatedly re-claim prize allocations, inflate their ticket balance, and liquidate the underlying tokens on PancakeSwap.

Following a Chainlink VRF draw resolution (requestId 1108) where the attacker won an external NFT prize, the attacker exploited a broken credit-consumption check in the PrizePool contract's award path. During prize claiming, the system failed to reduce the user's credit balance (CreditBurned remained at 0 across iterations). The attacker looped this execution ~20 times within a single transaction, re-awarding the same credit repeatedly to mint ~376.5M unearned ticket tokens.

The attacker then executed an InstantWithdrawal, paid a ~1.2% early exit fee (~4.6M tickets), redeemed ~372M underlying AMC tokens, and dumped the full supply on PancakeSwap V2 for ~154 WBNB before unwrapping to native BNB.

Attack Transactions:

Main Exploit: 0x29eb9725…08afc5

Liquidation: 0x99c9969a…85d3ba

Case & protocol details

Classification Gaming / Metaverse
Protocol Type Exploit/Reentrancy

Evidence & learning

Sources and on-chain records

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.