← Radar

Incident case file

Sign in to watch

FoxMarket Flash-Loan Stale Spot-Price Bond Mint Exploit

Incident date 2026-08-14Last updated Aug 26, 2026

0 views

ClosedBNB Smart ChainFlash-loan attack — stale AMM spot-price oracle manipulation (time-of-check/time-of-use)Cluster: FOX-BSC-2026-08

Estimated loss

$118.7K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

75%

Facts and investigation

Ledger

Attacker

EOA (funder): 0x5670d36f00bc7f6860b6afddb288e3668efc0ef9. Attack contract: 0x3a82a2a77061017927e5331fffd07c0308a1d2da (controlled by the EOA above). Confirmed verbatim by SlowMist's official technical alert.

Funds moved to

~119.14K USDT extracted, moved through multiple intermediary hops, and now sitting dormant at 0x005806c04ec29fe0740eb508c5f431c230b031e2 (traced by @AMLBotHQ on 17 August). No further movement observed. Attacker EOA was gas-funded with 1 BNB from FixedFloat approximately two months before the attack.

Linked

Victim (manipulated pair): 0xaab18bcdee287aea288c0560612caadf7c328803 (USDT/Fox PancakeSwap pair). Vulnerable contracts: FoxLpBondsPool 0x58e2a853bb14e46befd3148bd4280370fea4655a and Treasury 0x87614d97808dcdecb069fe8489848fa1c001e04d. Exploit transaction: 0x8e1775cbfd44db29744cc6687ff1822d2c47321de6e94062f789ad6181ad5514 at block 116169049, involving a ~$482M aggregated flash-loan trace (Lista DAO, Venus, Aave, Uniswap V4, PancakeSwap Infinity Vault) used purely as atomic working capital, and a

Chronology

1 beat
  1. T-2 months: Attacker EOA (0x5670d36f...) receives 1 BNB gas funding from FixedFloat, establishing operational capital ahead of the exploit. T0 (Aug 15, 2026, block 116169049): Attacker executes a single atomic transaction. FoxLpBondsPool.stake() calculates and fixes the _stakeAmount parameter from a manipulable PancakeSwap AMM spot quote before executing its own large USDT→Fox swap. That swap materially skews the pair reserves. The subsequent addLiquidity() call supplies Fox and USDT at a drastically different reserve ratio, but _stakeAmount is never recomputed from the actual deposited assets or fair LP value. Treasury.lpBonds() blindly trusts this stale, economically unsupported value, mints Fox based on it, and immediately transfers the inviter reward amount to the attacker-controlled referral address (0x3a82a2a7...). The attacker sells the newly minted Fox back into the pair within the same transaction, netting ~112,976-119,140 USDT. Aug 15 (same day): Defimon and monitoring bots flag the anomalous transaction in real time. Aug 15-17: SlowMist Hacked indexes the incident at $118,700. Aug 17, 06:43 UTC: @SlowMist_Team publishes the full technical alert with attacker and contract addresses verbatim. Aug 17-18: @AMLBotHQ traces the ~119.14K USDT to a dormant wallet (0x005806c...). An independent researcher publishes a full technical post-mortem ('A $482M Create Your Own Market Then Harvest Exploit') breaking down the flash-loan trace and the unbacked StakedFox liability. No recovery, compensation, or further response from the FoxMarket team has been publicly documented as of Aug 21.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)