TUR Staking Hack

Reported loss $133K
BNB Chain
Spot Price Manipulation

What happened

On 26 March 2026, a BNB Chain TUR staking contract with referral rewards was exploited for about $133.5K after its deposit valuation relied on live AMM reserve ratios.

Technical root cause

The Stake contract derived staking power from current TUR-NOBEL and NOBEL-USDT pool reserves rather than a manipulation-resistant oracle or TWAP; its referral-power distribution further allowed attacker-controlled referrers to claim oversized rewards.

How it happened

The attacker used a flash loan to manipulate the NOBEL-USDT and TUR-NOBEL pools, staked TUR while its on-chain valuation was inflated, then used self-controlled referrer accounts to claim amplified TUR rewards before swapping the proceeds back to USDT and repaying the loan.

Protocol details

Classification Oracle Manipulation
Protocol Type DeFi Protocol
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.