Incident case file
Sign in to watchDIP Token Double-Transfer Exploit — PancakeSwap Pool Drain
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: 0x0d4024cd27538350a911d9b7ee90811fa4875ba3
Timeline: On June 16, 2026, an attacker (0x0d4024cd27538350a911d9b7ee90811fa4875ba3) exploited a missing 'return' statement in the DIP token's _transfer() function. When 'from' or 'to' is the PancakeSwap Router, the function falls through and executes the same transfer twice. The attacker triggered this by calling skim(router) on the vulnerable PancakeSwap pair (0xf7d8267d01d1104da2dd30828aa9c0e1647919ef), causing a double DIP token transfer, then called sync() to set the pool's DIP reserve to an artificially low value — manipulating the AMM price and enabling the drain of 111,097.596667856001191208 USDC (~$111,098) from the pool. SlowMist published the TI Alert on June 17, 2026 with full attacker, pair, and vulnerable token addresses, along with a code-level citation: 'DIP token _transfer() function has a missing return statement in the router branch... This causes the same transfer to be executed twice when skim(router) is called on the Pancake Pair.' No recovery has been reported as of the publication of this report.
Sources and coverage
- Articlenews.symplexia.comhttps://news.symplexia.com/2026/06/new-economy/cryptocurrency/slowmist-a-single-missing-line-of-code-drained-111000-from-the-dip-token/
- Articlecryptotimes.iohttps://www.cryptotimes.io/2026/06/17/dip-token-bug-drains-111k-from-pancakeswap-pool/
- Articlegrafa.comhttps://grafa.com/en/news/crypto/dip-token-bug-drains-111k-from-pool
- Articlex.comhttps://x.com/SlowMist_Team
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)