Wiener DOGE Hack
What happened
On 25 April 2022 an attacker drained about 78 BNB (roughly $30,000) from the WDOGE/WBNB PancakeSwap pool of Wiener DOGE, a deflationary BEP-20 token on BNB Chain. WDOGE burned 4% of every transfer, and the contract did not exclude the liquidity pair from that fee when the pair itself was the sender. By pushing tokens into the pair and pulling them back out with skim(), the attacker made the pair pay the burn out of its own balance, shrank the pool's WDOGE reserve, and then sold WDOGE back into the distorted pool for more BNB than was borrowed.
How it happened
- The attacker flash-swapped 2,900 WBNB from the PancakeSwap BUSDT/WBNB pair.
- The 2,900 WBNB was swapped into the WDOGE/WBNB pair for about 6.6 trillion WDOGE.
- A large WDOGE amount was sent straight to the pair, leaving it holding more WDOGE than its recorded reserve.
- The attacker called
skim()to take the excess back. Because the pair was the sender, the 4% burn came out of the pair's balance, so it ended up with fewer WDOGE than before. sync()wrote the reduced WDOGE balance into the reserves, making WDOGE scarce and expensive in the pool.- The attacker sold the remaining WDOGE into the pair for about 2,978 WBNB, repaid the flash swap, and kept about 78 BNB.
Protocol details
Evidence
- report Solid Group tweet on WDOGE exploit (fxtwitter mirror) x.com
- analysis DeFiLlama defillama.com
- analysis Wiener DOGE Exploit certik.com
- analysis DeFiHackLabs past/2022 README: 20220424 Wiener DOGE - Flashloan raw.githubusercontent.com
- analysis DeFiHackLabs Wdoge_exp.sol PoC raw.githubusercontent.com
- analysis BscScan block 17248706 (first block after the PoC fork block) bscscan.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.