PYE Hack
What happened
PYE smart contract was exploited in a bunch of transactions. The example transaction:
https://bscscan.com/tx/0x3823a684…7fe2b1
The exploit occurred because of the lack of "k invariant verification" in the swap() routine, meaning that a caller verification was removed in the PYESwapPair. There are suspicions that this was an insider job.
The part of the stolen funds was deposited into the Tornado Cash mixer on the BNB chain, the rest was bridged to Ethereum and deposited into the mixer as well:
https://etherscan.io/address/0x85b86b43…0a92ee
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report twitter.com
- report Report twitter.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.