Incident case file
Sign in to watchATM Token — transferFrom() Auto-Swap Loophole Exploited on BSC
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: 0x7e7C1f0D567c0483f85e1d016718E44414CdBAFE (confirmed BscScan tx data, June 3 2026) | Funding pre-attack: MISSING — pre-attack EOA funding source not publicly disclosed
Timeline: June 3, 2026 12:25:23 UTC — Attacker (0x7e7C1f0D567c0483f85e1d016718E44414CdBAFE) executes exploit transaction (0x37b90a337...dcfd86) at block 102072357 on BNB Chain via attack contract 0xeCe23b48...97Dc9. The ATM token's custom transferFrom() function contains a hidden auto-swap mechanism converting 20% of any transferred amount into BSC-USD. The attacker repeatedly calls transferFrom(), triggering the swap mechanism each time, accumulating BSC-USD far in excess of normal token transfer expectations. Total extracted: ~$243,500 BSC-USD across 240 BEP-20 token transfers. June 4, 2026 — @TenArmorAlert publishes security alert: 'Our system has detected a suspicious attack involving #ATM on #BSC, resulting in an approximately loss of $243.5K. Attack transaction: bscscan.com/tx/0x37b90a337...' @CertiKAlert independently confirms: 'We have seen an exploit of ~$243K on ATM token.' Post June 4, 2026 — No post-mortem or official response from ATM team. Incident logged in SlowMist Hacked and Crypto Times. No recovery reported.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)