BSC TMM/USDT Hack
What happened
On April 4, 2026, the TMM/USDT PancakeSwap V2 pool on BNB Smart Chain was drained in a flash-loan-assisted reserve-manipulation attack. TMM was burned to the dead address, leaving the pool with about one TMM while its USDT side remained; the distorted pool state was then used to extract USDT. Reported net loss was about 1.665 million USDT.
An AMM-integrated token burn path could reduce the token balance held by its liquidity pool outside the normal swap-accounting flow. That created a material mismatch between pool balances and the reserve state used for pricing and accounting, allowing a flash-loan-funded attacker to manipulate the pool and extract USDT.
Case & protocol details
Attack Timeline
The attacker used same-transaction borrowing from several liquidity sources to acquire capital, manipulated the TMM/USDT pool by burning TMM to the dead address, and then traded against the resulting abnormal reserve state. The borrowed funds were repaid in the same transaction sequence; incident reporting estimates roughly 1.665 million USDT remained as profit.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report x.com
- analysis Halborn: Explained: The TMM Hack halborn.com
- analysis SlowMist Hacked: BSC TMM/USDT hacked.slowmist.io
- analysis BscScan TMM/USDT pair bscscan.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.