DIP Hack

Reported loss $111K
BNB Chain
Swap Logic Flaw

What happened

On June 16, 2026, an attacker drained about $111,000 from the DIP/AIC PancakeSwap pool on BNB Chain. The DIP token charges a sell fee on transfers and has a flaw in how it handles transfers involving the PancakeSwap router. The attacker combined the two with the pair's skim() and sync() functions to shrink the pool's recorded DIP reserve.

They then sold DIP into the distorted pool for almost all of its AIC and converted the proceeds to USDC. TenArmor flagged the attack in transaction 0x1c09395848a87069c9d6ddbe5adc6249510aba7a2a83479a74b4280cafb5fb29, and the DeFiHackLabs reproduction puts the profit at 111,097.59 USDC.

How it happened

  1. The attacker (0x0d4024cd27538350a911d9b7ee90811fa4875ba3) used an attack contract (0xddef10a85a5c67a9af8398d297aa51f8716383c7) to flash-swap 19,000,000 AIC from the AIC/NEX PancakeSwap pair.
  2. The contract swapped the borrowed AIC for DIP through the DIP/AIC pair.
  3. It sent the pair almost a full extra reserve's worth of DIP, sized to allow for DIP's 6% sell fee. It then called skim() with the PancakeSwap router as recipient, followed by sync(). DeFiHackLabs attributes the resulting collapse of the pair's DIP reserve to DIP's sell fee combined with a double router-transfer bug in the token.
  4. With the DIP reserve nearly empty, the contract sold its remaining DIP into the pair for almost all of the pair's AIC and repaid the flash swap plus fee.
  5. The leftover AIC was swapped to USDC and sent to the attacker, about 111,097.59 USDC.

Protocol details

Classification Protocol Logic
Protocol Type Token
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.