BIGO Hack
What happened
On January 14, 2025, BIGO token was exploited through its auto-burn mechanism, resulting in the hacker obtaining nearly all DOGE (about 18k in USD value) from the relevant PancakeSwap pair.
The attack stemmed from the _autoBurn function within the BIGO token’s transfer logic. When the attacker sent a small amount of ETH to the contract, they could set the burnAmount variable. After exchanging a large amount of DOGE for BIGO, they invoked the transfer function, triggering _autoBurn and drastically reducing the BIGO balance in the PancakeSwap pair.
With the pool now misaligned, the attacker swapped back to DOGE at a premium, draining almost all DOGE from the liquidity pool.
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report x.com
- report Report nickfranklin.site
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.