Incident case file
Sign in to watchJoe Agent ($JOE) — Single-Function Reentrancy in _removeLiquidityViaContract
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: Attacker EOA: 0xaa761779945dcc5f26064fc6dcb36ffab6ac7610. Attacker contract: 0x31f81fcd91025728f24bd6f0e4efb156e345a4cf.
Timeline: On 28 May 2026, an attacker drained about $45,000 (62.5 BNB and 1,195,918.92 JOE) from the Joe Agent ($JOE) project on BNB Smart Chain via a single-function reentrancy in _removeLiquidityViaContract. In that function, BNB is sent to the user with a low-level call before the contract updates lpInfo[user].lpAmount, so the require(lpInfo[user].lpAmount >= liquidity) check still passes during the callback. The attacker (EOA 0xaa761779...c7610, via contract 0x31f81fcd...a4cf) re-entered roughly 25 times, repeatedly withdrawing the same liquidity from the vulnerable proxy (0xef0f12d0...00c04, implementation 0xb12ce0a2...67319). The incident was detected and publicised by SlowMist (and corroborated by @Defi_Nerd_sec) the same day. Recovery: 0%.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)