← Radar

Incident case file

Sign in to watch

ATM Token — transferFrom() Auto-Swap Loophole Exploited on BSC

Incident date June 3, 2026

1 views

PausedBNB ChainSmart Contract / TokenomicsCluster: ATM-SWAP-2026-06

Estimated loss

$243.5K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

50%

Facts and investigation

Attacker: 0x7e7C1f0D567c0483f85e1d016718E44414CdBAFE (confirmed BscScan tx data, June 3 2026) | Funding pre-attack: MISSING — pre-attack EOA funding source not publicly disclosed

Funds moved to: ~$243,500 BSC-USD accumulated via repeated triggering of the auto-swap mechanism in ATM transferFrom(). Funds distributed across multiple BSC-USD recipient addresses post-exploit (visible in BscScan token transfers). Final destination not publicly traced. No recovery reported.
Attacker contract (Interacted With): 0xeCe23b485c38110b7a50B5067B7D4B644f897Dc9 | Exploit tx hash: 0x37b90a337075cd2feea93b12780abe9f953dad476e1c1418a02447aaa6dcfd86 | Block: 102072357 | Timestamp: Jun-03-2026 12:25:23 PM UTC (note: @TenArmorAlert tweeted alert on June 4 UTC — on-chain timestamp is June 3) | Core bug per @CertiKAlert: 'The transferFrom() includes logic to swap 20% transfer amount of ATM for BSC-USD, so the attacker can repeatedly swap out extra after transfer.' Method: Call Se

Timeline: June 3, 2026 12:25:23 UTC — Attacker (0x7e7C1f0D567c0483f85e1d016718E44414CdBAFE) executes exploit transaction (0x37b90a337...dcfd86) at block 102072357 on BNB Chain via attack contract 0xeCe23b48...97Dc9. The ATM token's custom transferFrom() function contains a hidden auto-swap mechanism converting 20% of any transferred amount into BSC-USD. The attacker repeatedly calls transferFrom(), triggering the swap mechanism each time, accumulating BSC-USD far in excess of normal token transfer expectations. Total extracted: ~$243,500 BSC-USD across 240 BEP-20 token transfers. June 4, 2026 — @TenArmorAlert publishes security alert: 'Our system has detected a suspicious attack involving #ATM on #BSC, resulting in an approximately loss of $243.5K. Attack transaction: bscscan.com/tx/0x37b90a337...' @CertiKAlert independently confirms: 'We have seen an exploit of ~$243K on ATM token.' Post June 4, 2026 — No post-mortem or official response from ATM team. Incident logged in SlowMist Hacked and Crypto Times. No recovery reported.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)