BNO Hack

TOTAL LOST $504K
Low Access Control Attacks bsc

What happened

BNO Pool was exploited due to incorrect reward calculation, resulting in a loss of 504,217 $USD.

The BNO pool, which supports both ERC20 and NFT staking, fell victim to an exploit. The attacker exploited an incorrect reward calculation issue and was able to drain the pool for 504,217 $USD. The exploit was executed in two transactions.

In the first transaction, the attacker drained over 700,000 $BNO tokens from the pool. The second transaction drained an additional 700,000 $BNO tokens, which were subsequently sold on PancakeSwap for $USDT.

Attacker Address:

https://bscscan.com/address/0xA6566574…2677fB

Funds Holder Address: https://bscscan.com/address/0xdc109426…d3c8cc

Malicious Transaction:

https://bscscan.com/tx/0x33fed54d…0096b9

https://bscscan.com/tx/0x16d75e42…76cc31

Malicious Contract Address:

https://bscscan.com/address/0xd138b9a5…1c13cd

Case & protocol details

Classification Token / Access Control
Protocol Type Exit Scam/Rugpull
Affected asset / contract BNO
Smart Contract Language Solidity
Official Website basedbento.com/
Protocol Twitter/X @BasedBento

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.