← Radar

Incident case file

Sign in to watch

Joe Agent ($JOE) — Single-Function Reentrancy in _removeLiquidityViaContract

Incident date May 28, 2026

0 views

ClosedBNB Smart ChainSmart contract exploit / reentrancyCluster: JOE-REENT-2026-05

Estimated loss

$45K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

50%

Facts and investigation

Attacker: Attacker EOA: 0xaa761779945dcc5f26064fc6dcb36ffab6ac7610. Attacker contract: 0x31f81fcd91025728f24bd6f0e4efb156e345a4cf.

Funds moved to: 62.5 BNB + 1,195,918.92 JOE extracted across 25 reentrancy loops (~$45K). Onward movement not detailed in available sources.
Attacker EOA: 0xaa761779945dcc5f26064fc6dcb36ffab6ac7610. Attacker contract: 0x31f81fcd91025728f24bd6f0e4efb156e345a4cf. Vulnerable JOE proxy: 0xef0f12d08d66e76e1866e60f30a0daa578e00c04. Vulnerable implementation: 0xb12ce0a21f67a9fc3c8ad1c7dbc4b017b7e67319. The exploit transaction hash and exact UTC timestamp are retrievable via the attacker EOA on BscScan.

Timeline: On 28 May 2026, an attacker drained about $45,000 (62.5 BNB and 1,195,918.92 JOE) from the Joe Agent ($JOE) project on BNB Smart Chain via a single-function reentrancy in _removeLiquidityViaContract. In that function, BNB is sent to the user with a low-level call before the contract updates lpInfo[user].lpAmount, so the require(lpInfo[user].lpAmount >= liquidity) check still passes during the callback. The attacker (EOA 0xaa761779...c7610, via contract 0x31f81fcd...a4cf) re-entered roughly 25 times, repeatedly withdrawing the same liquidity from the vulnerable proxy (0xef0f12d0...00c04, implementation 0xb12ce0a2...67319). The incident was detected and publicised by SlowMist (and corroborated by @Defi_Nerd_sec) the same day. Recovery: 0%.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)