← Radar

Incident case file

Sign in to watch

Little Boy Plus LBPHashrate Mint Exploit

Incident date June 18, 2026

1 views

ClosedBNB ChainSmart contract exploit — zero-value transferFrom bypass / unauthorized mintCluster: LBP-BSC-2026-06

Estimated loss

$377.6K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

90%

Facts and investigation

Attacker: 0x5449ded887576f43fc339851e942ebc1e6f8118b (contract created/funded by 0xb26DFE6b6180A30e2A2D9826867cc7e06631825a)

Funds moved to: 377,642.57 USDT (~610.555 BNB) drained via tx 0x55856d9fda4c5be5193561c7d775e823c3d6e499da44aab9da963daf61c50b0c (block 104727184). Final proceeds (~605.555 BNB, ~$354,656) forwarded to wallet 0x51578879...6096F6D1A; a smaller 5 BNB portion routed through a service labeled 'Puissant: Payment'. No recovery reported.
Victim pair: 0x00e3ea08fd8cbad955ec5d2292ad637670c31524. Vulnerable contract (LBPHashrate): 0x5e3cbc82d020be91a989eb747934104e9ab585fe. Attack funded via large flash loans (34M USDT from PancakeSwap Infinity Vault, 7.7M USDT from Lista DAO: Moolah), both borrowed and repaid within the same transaction.

Timeline: On June 18, 2026, attacker 0x5449ded887576f43fc339851e942ebc1e6f8118b exploited the LBPHashrate contract (0x5e3cbc82d020be91a989eb747934104e9ab585fe) of Little Boy Plus, a BNB Chain DeFi mining protocol advertised as having 'no team, no pre-mine, no admin keys.' The LBPHashrate._update() function could be triggered by zero-value transferFrom calls, bypassing OpenZeppelin's allowance check. By calling transferFrom(pair, DEAD, 0) without authorization, the attacker triggered _harvest(pair), which minted LBP tokens directly to the PancakeSwap pair address via LBP.mintReward(pair, reward) — inflating the pair's token balance without updating its tracked reserve, creating a reserve imbalance exploitable via PancakePair.swap(). The attacker used large flash loans (34M USDT from PancakeSwap Infinity Vault and 7.7M USDT from Lista DAO: Moolah, both borrowed and repaid atomically) to amplify the attack, ultimately draining 377,642.57 USDT (~610.555 BNB) in a single transaction (0x55856d9fda4c5be5193561c7d775e823c3d6e499da44aab9da963daf61c50b0c, block 104727184). SlowMist published the TI Alert the same day with full address disclosure. On-chain tracing shows the final proceeds (~605.555 BNB, ~$354,656) were forwarded to wallet 0x51578879...6096F6D1A, with a smaller 5 BNB portion routed through a service labeled 'Puissant: Payment'. No public statement has been issued by the Little Boy Plus team and no recovery has been reported.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)