CrowdRingCircle Hack
What happened
In July 2026, a BNB Chain attacker manipulated the CRC/USDT PancakeSwap pair after the CRC token's sell path burned tokens from the pair and re-synchronized its reserves. A reproducible forensic replay reports roughly 201,359 USDT of attacker profit.
CRC's transfer-to-pair sell path deducted tokens from the recipient pair's balance and called the pair's sync() function, allowing an attacker to manipulate the AMM reserve ratio.
How it happened
- The replay shows a flash-funded attack repeatedly sending CRC to the liquidity pair.
- Each transfer triggered the token's sell-destroy path against the pair balance and called sync(), distorting the pair's reserves; the attacker then exchanged CRC for USDT at the manipulated rate.
Protocol details
Evidence
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.