RANT Hack
What happened
On 5 July 2025 an attacker drained about $204,000 (roughly 311 BNB) from the PancakeSwap liquidity pool of the RANT token on BNB Chain. RANT's transfer logic had a "sell burn" feature meant to burn part of the pool's RANT whenever someone sold. Instead of sizing that burn from the pool's reserves, it removed exactly the amount the seller sent, so a large enough transfer could empty the pool of RANT and send its price sky-high.
The attacker funded the trade with a PancakeSwap V3 flash loan, bought a large amount of RANT, sent it to the token contract to trigger the burn, and sold into the now nearly RANT-free pool for BNB. Attack transaction: 0x2d9c1a00cf3d2fda268d0d11794ad2956774b156355e16441d6edb9a448e5a99; attacker: 0xad2cb8f48e74065a0b884af9c5a4ecbba101be23.
How it happened
- The attacker flash-borrowed WBNB from a PancakeSwap V3 pool.
- They used it to acquire a large amount of RANT from the RANT/WBNB pair.
- They transferred that RANT to the RANT token contract itself. Because the sender was not whitelisted,
_transfercalled_sellBurnLiquidityPairTokens(amount). - The function removed that same
amountof RANT straight out of the pair, splitting it between a burn address and therant_nodecontract, and then calledsync(). The pair was left with almost no RANT against its full WBNB reserve. - The attacker's RANT was sold into the skewed pair for far more WBNB than it cost. The attacker repaid the flash loan and kept about 311 BNB.
Protocol details
Evidence
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.