BRA Hack

Reported loss $225K
BNB Chain
Fee-on-transfer reserve accounting mismatch

What happened

On January 10, 2023, an attacker drained 819 WBNB (about $225,000) from the BRA token's PancakeSwap liquidity on BNB Chain in two transactions.

The BRA token charged a tax inside _transfer() and credited part of it to the liquidity pair. When the pair was both the sender and the recipient of a transfer, the pair was credited twice, and the token never called sync() on the pair afterward. The pair's BRA balance therefore grew past its recorded reserves on every such transfer, and anyone could collect the excess with skim().

The attacker funded the attack with a 1,400 WBNB flash loan from a DODO pool, pumped the pair's BRA balance with about 100 skim() calls that sent tokens from the pair back to the pair, and then sold the inflated BRA. The first transaction netted 675 WBNB and a second run netted 144 WBNB.

**Block data**

- Attacker: 0x67a909f2953fb1138bea4b60894b51291d2d0795 - Vulnerable contract: 0x449fea37d339a11efe1b181e5d5462464bba3752 - Exploit tx 1 (675 WBNB): 0x6759db55a4edec4f6bedb5691fc42cf024be3a1a534ddcc7edd471ef205d4047 - Exploit tx 2 (144 WBNB): 0x4e5b2efa90c62f2b62925ebd7c10c953dc73c710ef06695eac3f36fe0f6b9348

How it happened

  1. The attack contract borrowed 1,400 WBNB through flashLoan() on a DODO pool.
  2. It swapped 1,000 BNB for BRA (routed through USDT), receiving roughly 10.5K BRA, and transferred the BRA to the BRA/USDT PancakeSwap pair.
  3. It called skim() on the pair with the pair itself as the recipient. Because sender and recipient were both the pair, BRA's _transfer() tax logic credited the pair twice, so the pair ended up holding more BRA than before, with no sync() to update reserves.
  4. Repeating the skim() loop about 100 times inflated the pair's surplus BRA balance.
  5. The attacker skimmed the surplus out, sold it back to WBNB for about 1,675 WBNB, repaid the 1,400 WBNB loan and kept 675 WBNB. A second transaction repeated the method for 144 WBNB more.

Protocol details

Classification Token & Share Accounting
Protocol Type Exploit/Flash Loan Attack
Affected asset / contract BRA
Implementation language Solidity
Protocol links @TokenBra

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.