DIP Hack
What happened
On June 16, 2026, an attacker drained about $111,000 from the DIP/AIC PancakeSwap pool on BNB Chain. The DIP token charges a sell fee on transfers and has a flaw in how it handles transfers involving the PancakeSwap router. The attacker combined the two with the pair's skim() and sync() functions to shrink the pool's recorded DIP reserve.
They then sold DIP into the distorted pool for almost all of its AIC and converted the proceeds to USDC. TenArmor flagged the attack in transaction 0x1c09395848a87069c9d6ddbe5adc6249510aba7a2a83479a74b4280cafb5fb29, and the DeFiHackLabs reproduction puts the profit at 111,097.59 USDC.
How it happened
- The attacker (
0x0d4024cd27538350a911d9b7ee90811fa4875ba3) used an attack contract (0xddef10a85a5c67a9af8398d297aa51f8716383c7) to flash-swap 19,000,000 AIC from the AIC/NEX PancakeSwap pair. - The contract swapped the borrowed AIC for DIP through the DIP/AIC pair.
- It sent the pair almost a full extra reserve's worth of DIP, sized to allow for DIP's 6% sell fee. It then called
skim()with the PancakeSwap router as recipient, followed bysync(). DeFiHackLabs attributes the resulting collapse of the pair's DIP reserve to DIP's sell fee combined with a double router-transfer bug in the token. - With the DIP reserve nearly empty, the contract sold its remaining DIP into the pair for almost all of the pair's AIC and repaid the flash swap plus fee.
- The leftover AIC was swapped to USDC and sent to the attacker, about 111,097.59 USDC.
Protocol details
Evidence
- report TenArmor Security Alert on DIP (X post, via fxtwitter mirror) x.com
- code DeFiHackLabs: 20260616 DIP - Fee-on-Transfer Reserve Manipulation (README entry) github.com
- code DeFiHackLabs DIP_exp.sol proof of concept (read only, not executed) github.com
- analysis DeFiLlama defillama.com
- analysis BscScan block 104598279 bscscan.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.