MFT Hack
What happened
On November 17, 2024, an attacker drained about $33,700 of BSC-USD from the PancakeSwap pool of the MFT token on BNB Chain. MFT's transfer() burned tokens directly from the liquidity pool whenever a user sold. That let the attacker shrink the pool's MFT balance and then sell back into a pool whose reserves no longer matched its real balance.
The attack was funded with three chained PancakeSwap V3 flash loans of BSC-USD. TenArmor noted that the attacker then moved the profit into a pair they had created for another token, a pattern it had seen before and read as the sign of a seasoned attacker. No project response or recovery was found.
Attacker: 0x2bee9915ddefdc987a42275fbcc39ed178a70aaa. Attack contract: 0x6E088C3dD1055F5dD1660C1c64dE2af8110B85a8. Attack tx: 0xe24ee2af7ceee6d6fad1cacda26004adfe0f44d397a17d2aca56c9a01d759142.
How it happened
- The attacker borrowed BSC-USD through three nested PancakeSwap V3 flash loans.
- They made several MFT transfers to the MFT/BSC-USD pair to trigger the sell logic in
transfer(), so the MFT held by the token contract itself would not interfere later. - They bought a large amount of MFT with the borrowed BSC-USD, leaving the pair with very little MFT.
- They sold roughly the same amount of MFT back. Because
transfer()burns tokens from the pool on sells, the pool's balance fell further and the sale drained its BSC-USD. - They repaid the flash loans and kept about $33.7K.
Protocol details
Evidence
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.