PancakeHunny Hack
What happened
The attacker's address:
https://bscscan.com/address/0x0ef50be2…0db411
The attacker:
- WBNB was swapped to CAKE at PancakeSwap
- sent CAKE to the HUNNY Minter contract
- staked on CAKE-BNB Hive in PancakeHunny
- HUNNY Minter was “tricked” to mint more HUNNY tokens, namely:
using all the wallet balance to make HUNNYBNB LP, and then uses it to calculate the profit hunnyBnbAmount, which can be easily tampered with by just sending the tokens to the minter contract
- the attacker then un-staked from CAKE-BNB Hive to receive the HUNNY tokens from the Minter
- the attacker then sold the HUNNY tokens on PancakeSwap
Stolen funds were transferred to the external address and deposited to the Binance exchange wallet at:
https://bscscan.com/tx/0xcc88d376…1b8324
https://bscscan.com/tx/0xba23b86d…62a215
https://bscscan.com/tx/0x4c93ae86…79dac8
https://bscscan.com/tx/0xe8f8d0e3…dc3fab
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Post-mortem medium.com
- report Post-mortem medium.com
- report Report watchpug.medium.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.