FlyCow Hack
What happened
On July 17, 2026, on-chain analysis reported that FlyCow (FCOW) was exploited for an estimated $65,258 in USDT and BNB routed to attacker-controlled addresses.
How it happened
The published analysis describes a reserve-manipulation attack on an unverified FCOW contract: it reports that the token transfer path burned FCOW from a PancakeSwap pair and called sync during transfer processing, distorting the pair's output calculation. The mechanism is a behavioral reconstruction from traces and storage events, not verified source code.
Protocol details
Evidence
- analysis FlyCow (FCOW) Exploit Analysis anomly.rs
- analysis DeFiLlama defillama.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.