Incident case file
Sign in to watchBYToken — Public triggerAutoBurn() Abused via Flashloan to Skew Pool Reserves
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: 0x047547A4fa4a67C1032d249B49EC1a79c0460BAD (confirmed BscScan tx data, June 4 2026) | Funding pre-attack: MISSING — pre-attack EOA funding source not publicly disclosed
Timeline: June 4, 2026 20:38:09 UTC — Attacker (0x047547A4fa4a67C1032d249B49EC1a79c0460BAD) executes exploit transaction (0xe31c681e...80979) at block 102329719 on BNB Chain. Step 1: flashloan ~422,497 WBNB (~$252M notional) from Lista DAO Moolah. Step 2: swap portion into PancakeSwap to acquire BY tokens. Step 3: call public triggerAutoBurn() function — internally calls _autoBurn(allowPoolBurn=true) which burns ~67,800 BY tokens directly from the PancakePair contract and calls pair.sync() to rewrite reserves. Step 4: exploit the resulting extreme BY/WBNB ratio imbalance (1 BY vs full WBNB reserve) to extract ~146.60 BNB plus residual. Step 5: repay flashloan. Net profit: ~146.60 BNB (~$84,426 at block / ~$87,402 per TenArmor at tweet time). MEV fee: 7 BNB to Puissant Payment. June 5, 2026 04:28 UTC — @TenArmorAlert publishes security alert: 'Our system has detected a suspicious attack involving #BY token on #BSC, resulting in an approximately loss of $88.4K. Attack transaction: bscscan.com/tx/0xe31c681ee...' Post June 5, 2026 — No post-mortem or official response from BY token team. Incident logged in SlowMist Hacked (amount listed as $87,402) and Crypto Times ($88.4K per TenArmor tweet). No recovery reported.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)