TUR Staking Hack
What happened
On 26 March 2026, a BNB Chain TUR staking contract with referral rewards was exploited for about $133.5K after its deposit valuation relied on live AMM reserve ratios.
The Stake contract derived staking power from current TUR-NOBEL and NOBEL-USDT pool reserves rather than a manipulation-resistant oracle or TWAP; its referral-power distribution further allowed attacker-controlled referrers to claim oversized rewards.
How it happened
The attacker used a flash loan to manipulate the NOBEL-USDT and TUR-NOBEL pools, staked TUR while its on-chain valuation was inflated, then used self-controlled referrer accounts to claim amplified TUR rewards before swapping the proceeds back to USDT and repaying the loan.
Protocol details
Evidence
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.