← Radar

Incident case file

Sign in to watch

Dream Health Chain Award-Logic Exploit — $71.8K Loss

Incident date Sep 4, 2026Last updated Sep 24, 2026

0 views

ContainedBNB ChainState-machine logic flaw / repeated claim exploitCluster: DREAMHEALTH-BNB-2026-09

Estimated loss

$71.9K

Affected users

1
Group joining is coming soon.

Investigation

85%

Facts and investigation

Ledger

Attacker

0xd3a8d0a9f55cf679fff6f277e49afc95b49d2b07

Funds moved to

Extracted repeatedly from the shared proxy balance and immediately sold into the project's own trading pools, contributing to an ~80% price collapse.

Linked

Attacker: 0xd3a8d0a9f55cf679fff6f277e49afc95b49d2b07. Victim proxy: 0xe2a047aadbac51b0116af1ce91ebdae4b4202094. Vulnerable implementation: 0x5abb3fe2a02e5d4320862944cd3a0b8f6af28ce1. Exploit contract: 0x226923d34a10f3d54b57b9f4b685e82c6cba968a.

Chronology

1 beat
  1. On September 5, 2026, an attacker exploited a business logic flaw in Dream Health Chain's award-distribution state machine on BNB Chain. The createAward() function recorded a fixed reward without locking any collateral or per-award reserve. The participateAward() function failed to require that an award be unclaimed before allowing a claim, meaning a claimed award (status=2) could be reset back to unclaimed (status=1) for as little as a 0-1 wei transfer. claimAward() would then pay the same fixed reward repeatedly from the shared proxy balance. The attacker automated this loop, draining roughly 95% of the rewards pool in under one second, and immediately sold the stolen tokens into the project's own trading pools for approximately $71,800 in USDT-equivalent value. The token's market price fell roughly 80% as a result, spreading additional losses across more than 35,000 holders and liquidity providers. The project's code had never been publicly verified or audited, and had been largely dormant since 2022.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)