BSC TMM/USDT Hack

TOTAL LOST $1.7M
Medium Access Control Attacks bsc

What happened

On April 4, 2026, the TMM/USDT PancakeSwap V2 pool on BNB Smart Chain was drained in a flash-loan-assisted reserve-manipulation attack. TMM was burned to the dead address, leaving the pool with about one TMM while its USDT side remained; the distorted pool state was then used to extract USDT. Reported net loss was about 1.665 million USDT.

Technical Root Cause

An AMM-integrated token burn path could reduce the token balance held by its liquidity pool outside the normal swap-accounting flow. That created a material mismatch between pool balances and the reserve state used for pricing and accounting, allowing a flash-loan-funded attacker to manipulate the pool and extract USDT.

Case & protocol details

Classification Protocol Logic / Reserve Manipulation
Smart Contract Language Solidity

Attack Timeline

The attacker used same-transaction borrowing from several liquidity sources to acquire capital, manipulated the TMM/USDT pool by burning TMM to the dead address, and then traded against the resulting abnormal reserve state. The borrowed funds were repaid in the same transaction sequence; incident reporting estimates roughly 1.665 million USDT remained as profit.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.