MCN Labs Hack

Reported loss $93K
Other

What happened

On September 30, 2026, the MCN Labs LPBonus contract on BNB Smart Chain was exploited for ~$92,600 USD (1,442,165.71 FIST) due to a reward accounting logic flaw that used inconsistent MSN reserve values during reward accrual versus withdrawal calculations.

The vulnerability was located in MCN Labs' LPBonus contract (0x5227...), which used inconsistent MSN reserve values to track reward distributions. The AddFistFee function updated the global reward index (oneshareFIST) by dividing newly acquired FIST rewards by the MSN reserve present at accrual time. However, CalcPendingUser later multiplied this index by a user weight calculated from the MSN reserve present at claim time.

The attacker manipulated the reserve down to ~89.33 MSN during reward accrual, then inflated it to ~491.11 MSN before executing UserRemoveLp. This calculation mismatch enabled a newly registered LP to claim 1,442,165.71 FIST despite the intervening reward pool receiving only 940,041.61 FIST in legitimate funding.

Attack Transaction Hash: 0xecac1563…808e6b

Attacker Address: 0xb6fff29d…e76f7a

Vulnerable Contract: 0x52272524…bb054b

Protocol details

Classification Other
Protocol Type Exploit/Other
Protocol links @MCNLabs

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.