Incident case file
Sign in to watchAROS — Smart Contract Exploit Drains AROS/USDT PancakeSwap Pool on BSC
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: 0x6f548693937039C8C4343E01C5bd42c5986508f5 (confirmed by @TenArmorAlert June 1 2026 and BscScan tx data) | Funded by: 0x7A4731D5...37BF828FE (9 days before exploit per BscScan address overview)
Timeline: May 30, 2026 18:24:07 UTC — Attacker executes exploit transaction (0xe89fe640...abf41e1) at block 101353585 on BNB Chain. The attack uses a flashloan from Lista DAO Moolah (~427K WBNB) as leverage, interacts with the AROS/USDT PancakeSwap V2 pool, and drains approximately $295,300 USDT. The transaction involves 80 BEP-20 token transfers and uses method 0xc7cc670d. June 1, 2026 06:33 UTC — @TenArmorAlert publishes security alert: 'Our system has detected a suspicious attack involving #AROS on #BSC, resulting in an approximately loss of $295.3K. Attack transaction: bscscan.com/tx/0xe89fe640e...' Post June 1, 2026 — No post-mortem published. No official response from AROS team. Root cause not detailed publicly. Incident classified as 'suspicious attack' by TenArmor. SlowMist Hacked confirms incident with $295,300 loss and 'Smart Contract Vulnerability' attack method.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)