MFT Hack

Reported loss $34K
BNB Chain
Unknown

What happened

On November 17, 2024, an attacker drained about $33,700 of BSC-USD from the PancakeSwap pool of the MFT token on BNB Chain. MFT's transfer() burned tokens directly from the liquidity pool whenever a user sold. That let the attacker shrink the pool's MFT balance and then sell back into a pool whose reserves no longer matched its real balance.

The attack was funded with three chained PancakeSwap V3 flash loans of BSC-USD. TenArmor noted that the attacker then moved the profit into a pair they had created for another token, a pattern it had seen before and read as the sign of a seasoned attacker. No project response or recovery was found.

Attacker: 0x2bee9915ddefdc987a42275fbcc39ed178a70aaa. Attack contract: 0x6E088C3dD1055F5dD1660C1c64dE2af8110B85a8. Attack tx: 0xe24ee2af7ceee6d6fad1cacda26004adfe0f44d397a17d2aca56c9a01d759142.

How it happened

  1. The attacker borrowed BSC-USD through three nested PancakeSwap V3 flash loans.
  2. They made several MFT transfers to the MFT/BSC-USD pair to trigger the sell logic in transfer(), so the MFT held by the token contract itself would not interfere later.
  3. They bought a large amount of MFT with the borrowed BSC-USD, leaving the pair with very little MFT.
  4. They sold roughly the same amount of MFT back. Because transfer() burns tokens from the pool on sells, the pool's balance fell further and the sale drained its BSC-USD.
  5. They repaid the flash loans and kept about $33.7K.

Protocol details

Classification Protocol Logic
Protocol Type DeFi Protocol
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.