Pepe Trump Hack
What happened
On June 30, 2026, the Pepe Trump ($PEPETrump) project on the BNB Chain executed a malicious rug pull, draining approximately $38,500 from its primary PancakeSwap liquidity pool.
The rug pull was orchestrated via a pre-programmed backdoor embedded in the token's non-standard architecture. The PEPEToken contract overrode the standard ERC-20 balanceOf() function, delegating all balance queries to an external, upgradeable contract named LockupContractFactory.
Immediately before the drain, the deployers upgraded the LockupContractFactory logic to introduce a malicious function selector (0x801425e6). This allowed the attacker to inject arbitrary state variables and manipulate the balance records returned for the PancakePair address. By spoofing the pool's internal token tracking, the deployers cleanly skewed the AMM pricing logic and siphoned out the paired liquidity into the hacker's wallet.
Vulnerable Token Contract: 0xc8168896…7Cd17f
Protocol details
Evidence
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.