LAXO Token Hack
Incident Overview
On February 22, 2026, the LAXO token on BSC suffered $190,540 in losses across four exploit transactions when attackers discovered and exploited the same burn-before-sync vulnerability, with three copycat attackers replicating the attack within 13 minutes of the initial exploit.
The first attacker flash-loaned 350,000 BSC-USD and swapped it for 43.2M LAXO tokens sent to the fee-exempt PancakeSwap router. By adding and removing minimal liquidity, the attacker retrieved the tokens without fees. When transferring 52M LAXO to trigger a swap, the contract automatically capped the amount, deducted a sell fee, and burned 41M LAXO before calling sync() to update pool balances.
The pool calculated the BSC-USD return based on the post-burn supply, valuing the remaining ~13M LAXO tokens at the original pool balance and allowing extraction of far more BSC-USD than invested. The first exploiter executed this twice for $182K profit. Within 13 minutes, two copycat attackers identified the vulnerability from the public transaction and executed their own versions, extracting an additional $8K combined (with one paying most gains as MEV bribes).
Incident Report
Protocol Information
Market Context at Time of Hack
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to LAXO Token, these are the critical security checks that could have prevented this incident (February 2026).
- Verify all logic paths related to Flash Loan Attack are guarded by proper access controls and input validation - see the Flash Loans Attacks attack class for patterns
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialRelated Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Proof-of-Concept Exploits
On-Chain Evidence & References
- Twitter/X Alert https://x.com/CertiKAlert/status/2027317095420072317
Sources & References
Learn to Prevent the Next LAXO Token
The LAXO Token hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.