Future Protocol Hack
What happened
On 2 July 2025 an attacker drained about $4.6 million in USDT from the PancakeSwap FPC/USDT pool on BNB Smart Chain by abusing Future Protocol's FPC token. When FPC was sold into the pool, the token contract burned a fee and moved tokens straight out of the pool's balance, then called sync before the seller's tokens arrived. That set the pool's recorded FPC reserve to almost nothing while the USDT reserve stayed high, so the pool priced FPC far too high and paid out most of its USDT.
The attack ran in one transaction, 0x3a9dd216fb6314c013fa8c4f85bfbbe0ed0a73209f54c57c1aab02ba989f5937, from attacker address 0x18dd258631b23777c101440380bf053c79db3d9d. A 23.02 million USDT flash loan paid for it, and the attacker kept about 4.67 million USDT after repaying the loan. No recovery has been reported.
How it happened
- The attacker flash-borrowed 23,020,000 USDT from a USDT/USDC pool.
- They swapped all of it for FPC in the FPC/USDT pair, cutting the pair's FPC reserve to about 160,836 FPC.
- They sold 247,441 FPC back into the pair. During the transfer the FPC contract burned 65% of the amount and moved about 160,836.76 FPC out of the pair to treasury and reward pools, then called
syncbefore the rest of the attacker's tokens reached the pair. - The pair's recorded FPC reserve dropped to about 0.000065 FPC while its USDT reserve was unchanged, so the swap paid out 27,693,883 USDT.
- The attacker repaid the 23.02 million USDT loan and kept about 4.67 million USDT.
Protocol details
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.