← Radar

Incident case file

Sign in to watch

DIP Token Double-Transfer Exploit — PancakeSwap Pool Drain

Incident date June 16, 2026

1 views

ClosedBNB ChainSmart contract exploit — missing return statement / double-transfer logic flawCluster: DIP-BSC-2026-06

Estimated loss

$111.1K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Attacker: 0x0d4024cd27538350a911d9b7ee90811fa4875ba3

Funds moved to: 111,097.596667856001191208 USDC (~$111,098) drained from the PancakeSwap DIP/USDC liquidity pool. No recovery reported; no further cash-out path publicly disclosed.
Victim pair (PancakeSwap): 0xf7d8267d01d1104da2dd30828aa9c0e1647919ef. Vulnerable token contract (DIP): 0x6c60bf5db0670ae94489d3dde2c60f271625db50.

Timeline: On June 16, 2026, an attacker (0x0d4024cd27538350a911d9b7ee90811fa4875ba3) exploited a missing 'return' statement in the DIP token's _transfer() function. When 'from' or 'to' is the PancakeSwap Router, the function falls through and executes the same transfer twice. The attacker triggered this by calling skim(router) on the vulnerable PancakeSwap pair (0xf7d8267d01d1104da2dd30828aa9c0e1647919ef), causing a double DIP token transfer, then called sync() to set the pool's DIP reserve to an artificially low value — manipulating the AMM price and enabling the drain of 111,097.596667856001191208 USDC (~$111,098) from the pool. SlowMist published the TI Alert on June 17, 2026 with full attacker, pair, and vulnerable token addresses, along with a code-level citation: 'DIP token _transfer() function has a missing return statement in the router branch... This causes the same transfer to be executed twice when skim(router) is called on the Pancake Pair.' No recovery has been reported as of the publication of this report.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)