ATM Token Hack
What happened
On June 4, 2026, ATM Token's BSC liquidity was exploited for approximately $243,500. The reported drain came from the ATM/USDT PancakeSwap pair.
ATMToken's custom transfer path allowed its own token balance to be sold into the liquidity pair at zero minimum output during sells, while the anti-whale and sell-lock controls were keyed to easily reset per-address state.
Case & protocol details
How it happened
A reconstructed on-chain replay shows the attacker accumulated ATM, distributed it across fresh helper addresses, then sold those balances into the pumped ATM/USDT pair. Each sell retriggered the token's internal auto-swap, compounding the extraction from the pair.
Evidence & learning
Proofs of concept
2 availableSources and on-chain records
- report Report x.com
- transaction ATM Token drain transaction bscscan.com
- analysis Website reference hacked.slowmist.io
- analysis Twitter/X Alert x.com
- analysis DeFiHackLabs ATM Token exploit replay raw.githubusercontent.com
- analysis SlowMist Hacked: ATM Token hacked.slowmist.io
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.