MCN Labs Hack
What happened
On September 30, 2026, the MCN Labs LPBonus contract on BNB Smart Chain was exploited for ~$92,600 USD (1,442,165.71 FIST) due to a reward accounting logic flaw that used inconsistent MSN reserve values during reward accrual versus withdrawal calculations.
The vulnerability was located in MCN Labs' LPBonus contract (0x5227...), which used inconsistent MSN reserve values to track reward distributions. The AddFistFee function updated the global reward index (oneshareFIST) by dividing newly acquired FIST rewards by the MSN reserve present at accrual time. However, CalcPendingUser later multiplied this index by a user weight calculated from the MSN reserve present at claim time.
The attacker manipulated the reserve down to ~89.33 MSN during reward accrual, then inflated it to ~491.11 MSN before executing UserRemoveLp. This calculation mismatch enabled a newly registered LP to claim 1,442,165.71 FIST despite the intervening reward pool receiving only 940,041.61 FIST in legitimate funding.
Attack Transaction Hash: 0xecac1563…808e6b
Attacker Address: 0xb6fff29d…e76f7a
Vulnerable Contract: 0x52272524…bb054b
Protocol details
Evidence
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.