Smart Bank Token Hack
What happened
Smart_Bank on BNB Chain was drained after its lending logic valued SBT from the contract’s own instantly mutable balances. An attacker used a PancakeSwap V3 flash loan to inflate the internal SBT price, then borrowed the bank’s USDT reserve against collateral that was materially under-valued outside the manipulated calculation.
Smart_Bank used a self-referential spot price—its own USDT balance divided by its own SBT balance—as the collateral oracle. A caller could move both values with Buy_SBT and immediately borrow against the manipulated quote in the same transaction. The startup gate was also permissionless and based only on a temporarily donated USDT balance.
Case & protocol details
Attack Timeline
The attacker flash-borrowed 1.95M BSC-USD/USDT, transferred 950K to Smart_Bank to meet its public startup threshold, and enabled trading. They bought 20M SBT, raising the bank’s USDT balance while reducing its SBT inventory. Because Smart_Bank quoted SBT using that live balance ratio, the transaction inflated the collateral price immediately.
The attacker then borrowed 1,966,930 USDT while locking 1,299,884 SBT, repaid the flash loan, and retained about $56K from the bank’s reserve.
Evidence & learning
Sources and on-chain records
- report Report x.com
- transaction Transaction bscscan.com
- code Code reference github.com
- analysis Verified Smart_Bank contract bscscan.com
- analysis SlowMist BSC incident record hacked.slowmist.io
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.