CrowdRingCircle Hack

Reported loss $209K
BNB Chain
Incorrect Share Accounting

What happened

In July 2026, a BNB Chain attacker manipulated the CRC/USDT PancakeSwap pair after the CRC token's sell path burned tokens from the pair and re-synchronized its reserves. A reproducible forensic replay reports roughly 201,359 USDT of attacker profit.

Technical root cause

CRC's transfer-to-pair sell path deducted tokens from the recipient pair's balance and called the pair's sync() function, allowing an attacker to manipulate the AMM reserve ratio.

How it happened

  1. The replay shows a flash-funded attack repeatedly sending CRC to the liquidity pair.
  2. Each transfer triggered the token's sell-destroy path against the pair balance and called sync(), distorting the pair's reserves; the attacker then exchanged CRC for USDT at the manipulated rate.

Protocol details

Classification Token & Share Accounting
Protocol Type Token
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.