Little Boy Plus Hack

Reported loss $367K
BNB Chain
Arithmetic Error

What happened

Little Boy Plus was exploited on BNB Chain on 17 June 2026. The attacker used a single atomic transaction to create an imbalance between the LBP/USDT pair's token balance and recorded reserves, then swapped out USDT. Public incident reporting placed the loss at roughly $367,000 to $378,000.

Technical root cause

LBPHashrate._update() reportedly executed _harvest() for a zero-value transfer, allowing a third party to trigger mintReward for the pair. The resulting token balance increase was not reflected in the pair's recorded reserves.

How it happened

  1. The reported path used a zero-value transferFrom call on behalf of the liquidity pair to trigger reward harvesting.
  2. Reward tokens were minted to the pair without updating its reserves; the attacker then exploited the balance-versus-reserve mismatch through a swap, with flash liquidity used in the transaction.

Protocol details

Classification Token & Share Accounting
Protocol Type Token
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.