BYC Token Hack

Reported loss $100K
BNB Chain
Incorrect Fee Accounting

What happened

The BYC token (listed by SlowMist as RunWay) on BNB Chain was exploited on December 3, 2024, and about $100,000 in USDT was drained from its PancakeSwap BYC/USDT pool. BYC had an autoBurnLiquidity function that burned BYC out of the pair once a threshold, lpBurnFrequency, was reached, and that threshold grew whenever BYC was sent to the pair. The attacker inflated the threshold by pushing a large amount of BYC into the pair, then triggered the burn.

The burn left the pool holding almost no BYC, so a small amount of BYC could buy nearly all of its USDT.

How it happened

  1. The attacker swapped a large amount of USDT for BYC in the PancakeSwap BYC/USDT pair.
  2. It transferred all of that BYC back to the pair. The transfers increased lpBurnFrequency, the amount the burn logic would take from the pair.
  3. It called autoBurnLiquidity, which sent BYC from the pair to the dead address and cut the pair's BYC reserve to about 1 token.
  4. With the BYC reserve almost empty, the attacker swapped BYC into the pair and withdrew nearly all of its USDT, about $100,000.

Protocol details

Classification Token & Share Accounting
Protocol Type Token

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.