BYToken Hack

TOTAL LOST $89K
Low Flash Loan Attacks bsc

What happened

On June 4, 2026, BYToken's BY/WBNB liquidity pool on BSC lost about 146.60 WBNB (approximately $88,550) after its public auto-burn path was used to distort the pair's reserves.

Technical Root Cause

BYToken exposed triggerAutoBurn() without an access-control restriction. When its own balance was empty, the reachable path could burn BY from the AMM pair and call sync(), allowing the pair's reserve ratio to be manipulated.

Case & protocol details

Classification Token
Protocol Type Exploit/Flash Loan Attack
Official Website bostoken.co
Protocol Twitter/X @bosblockchain

Attack Timeline

The attacker obtained temporary BY liquidity from an on-chain flash-loan vault, shaped the BY/WBNB reserves, then called the unrestricted auto-burn path. The burn and sync() left the pool with a severely distorted reserve ratio, after which swaps drained its WBNB liquidity.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.