← Radar

Incident case file

Sign in to watch

AROS — Smart Contract Exploit Drains AROS/USDT PancakeSwap Pool on BSC

Incident date May 30, 2026

1 views

PausedBNB ChainSmart Contract / DeFiCluster: AROS-SC-2026-05

Estimated loss

$295.3K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

25%

Facts and investigation

Attacker: 0x6f548693937039C8C4343E01C5bd42c5986508f5 (confirmed by @TenArmorAlert June 1 2026 and BscScan tx data) | Funded by: 0x7A4731D5...37BF828FE (9 days before exploit per BscScan address overview)

Funds moved to: ~$295,300 USDT drained from PancakeSwap V2 BSC-USD/AROS pool (0x3104d26ae74b49eec61675a873b38414329c5edd). Funds split across multiple BSC-USD transfers to several recipient addresses post-exploit (visible in BscScan token transfer history). Final destination not publicly traced by any firm. Flashloan from Lista DAO Moolah used as leverage (~427K WBNB / ~$252M notional) — profit net $295,300.
Attacker contract (self-interacting): 0x6f548693937039C8C4343E01C5bd42c5986508f5 (From = To on exploit tx, confirmed BscScan) | PancakeSwap V2 BSC-USD/AROS pool (victim): 0x3104d26ae74b49eec61675a873b38414329c5edd | Exploit tx hash: 0xe89fe640ec5241edfca7d8dcae77a0a4270dee15e4bbd043fc60e393aabf41e1 | Block: 101353585 | Timestamp: May-30-2026 06:24:07 PM UTC | Method: 0xc7cc670d | BEP-20 Tokens Transferred: 80 | Flashloan source: Lista DAO Moolah (~427,489 WBNB + 15,089,844 BSC-USD). Root cause:

Timeline: May 30, 2026 18:24:07 UTC — Attacker executes exploit transaction (0xe89fe640...abf41e1) at block 101353585 on BNB Chain. The attack uses a flashloan from Lista DAO Moolah (~427K WBNB) as leverage, interacts with the AROS/USDT PancakeSwap V2 pool, and drains approximately $295,300 USDT. The transaction involves 80 BEP-20 token transfers and uses method 0xc7cc670d. June 1, 2026 06:33 UTC — @TenArmorAlert publishes security alert: 'Our system has detected a suspicious attack involving #AROS on #BSC, resulting in an approximately loss of $295.3K. Attack transaction: bscscan.com/tx/0xe89fe640e...' Post June 1, 2026 — No post-mortem published. No official response from AROS team. Root cause not detailed publicly. Incident classified as 'suspicious attack' by TenArmor. SlowMist Hacked confirms incident with $295,300 loss and 'Smart Contract Vulnerability' attack method.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)