Sheep Hack

Reported loss $3K
BNB Chain
Incorrect Share Accounting

What happened

On February 10, 2023, an attacker took about 16.39 WBNB from the SHEEP token's PancakeSwap pool on BNB Chain. SHEEP is a reflection token, where each balance is derived from a shared exchange rate. Its public burn() function did not keep its two internal supplies consistent. Every burn raised the rate and shrank every holder's balanceOf, including the pool's. After enough burns the pool's SHEEP balance fell to almost nothing. The attacker then called sync() to lock that in as the pool reserve and sold a tiny amount of SHEEP for about 396 WBNB, most of which was its own flash-loaned 380 WBNB. The pool's WBNB reserve fell from about 38.47 to 22.08 WBNB.

DeFiHackLabs lists the loss as about $3K. A reproduction of the attack transaction shows about 16.39 WBNB of net profit. BlockSec called it another case of the same deflation-token flaw and said it had found 15 attack transactions on Ethereum and BSC exploiting the same vulnerability in similar tokens.

How it happened

  1. The attacker flash-borrowed 380 WBNB from a DODO pool and swapped it for SHEEP.
  2. It repeatedly called SHEEP.burn(balance) while the pair's SHEEP.balanceOf was above 2. _burn subtracted the plain token amount from the burner's much larger reflection balance but reduced _tTotal by the full amount. That pushed up the rate used to convert reflection balances into token balances, so the pair's reported SHEEP balance kept shrinking even though no tokens left it.
  3. It called Pair.sync(), which set the pair's SHEEP reserve to the shrunken balance (about 1 wei) against roughly 418 WBNB.
  4. It sold its small remaining SHEEP balance into the pair and received about 396.39 WBNB, repaid the 380 WBNB loan and kept about 16.39 WBNB. Attack tx: 0x61293c6dd5211a98f1a26c9f6821146e12fb5e20c850ad3ed2528195c8d4c98e.

Protocol details

Classification Token & Share Accounting
Protocol Type Token
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.