LML/USDT staking protocol Hack
What happened
At the 31 March/1 April 2026 reporting boundary, the LML staking protocol on BNB Chain was exploited for about $950,000 through manipulation of the LML/USDT market and its reward-claim path.
Reward accrual used a stored LML/USDT price protected by a 3600-second cooldown, while redemption depended on the live AMM value; the contract had no deviation check linking those two prices.
Case & protocol details
Attack Timeline
The attacker used flash liquidity to distort the LML/USDT market, then used EIP-7702 delegation to batch-trigger reward claims from 11 pre-staked EOAs. The resulting LML was sold into the distorted pool after the reward path depleted its reserves.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.