PGNLZ token Hack

TOTAL LOST $100K
Low Flash Loan Attacks bnb smart chain

What happened

On January 27, 2026, the USDT-PGNLZ PancakeSwap V2 pool on BNB Smart Chain was exploited for approximately $100,000.

Technical Root Cause

PGNLZ's burn mechanism could remove PGNLZ directly from the liquidity-pool balance. The resulting reserve imbalance made the pool price manipulable.

Case & protocol details

Classification Token
Protocol Type Exploit/Flash Loan Attack
Official Website excoms.io
Protocol Twitter/X @wttpp81197815

Attack Timeline

The attacker invoked the token's faulty pool-burn path to reduce PGNLZ reserves, distort the pool price, and drain USDT through swaps.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.