Incident case file
Sign in to watchDream Health Chain Award-Logic Exploit — $71.8K Loss
0 views
Estimated loss
Affected users
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatOn September 5, 2026, an attacker exploited a business logic flaw in Dream Health Chain's award-distribution state machine on BNB Chain. The createAward() function recorded a fixed reward without locking any collateral or per-award reserve. The participateAward() function failed to require that an award be unclaimed before allowing a claim, meaning a claimed award (status=2) could be reset back to unclaimed (status=1) for as little as a 0-1 wei transfer. claimAward() would then pay the same fixed reward repeatedly from the shared proxy balance. The attacker automated this loop, draining roughly 95% of the rewards pool in under one second, and immediately sold the stolen tokens into the project's own trading pools for approximately $71,800 in USDT-equivalent value. The token's market price fell roughly 80% as a result, spreading additional losses across more than 35,000 holders and liquidity providers. The project's code had never been publicly verified or audited, and had been largely dormant since 2022.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)