BYToken Hack
What happened
On June 4, 2026, BYToken's BY/WBNB liquidity pool on BSC lost about 146.60 WBNB (approximately $88,550) after its public auto-burn path was used to distort the pair's reserves.
BYToken exposed triggerAutoBurn() without an access-control restriction. When its own balance was empty, the reachable path could burn BY from the AMM pair and call sync(), allowing the pair's reserve ratio to be manipulated.
Case & protocol details
Attack Timeline
The attacker obtained temporary BY liquidity from an on-chain flash-loan vault, shaped the BY/WBNB reserves, then called the unrestricted auto-burn path. The burn and sync() left the pool with a severely distorted reserve ratio, after which swaps drained its WBNB liquidity.
Evidence & learning
Attack pattern
Compare incidents →Proof of concept
1 availableSources and on-chain records
- report Report x.com
- transaction Transaction bscscan.com
- analysis Website reference hacked.slowmist.io
- analysis anomly.rs: BYToken Auto-Burn + sync() Exploit Analysis anomly.rs
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.