Incident case file
Sign in to watchLittle Boy Plus LBPHashrate Mint Exploit
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: 0x5449ded887576f43fc339851e942ebc1e6f8118b (contract created/funded by 0xb26DFE6b6180A30e2A2D9826867cc7e06631825a)
Timeline: On June 18, 2026, attacker 0x5449ded887576f43fc339851e942ebc1e6f8118b exploited the LBPHashrate contract (0x5e3cbc82d020be91a989eb747934104e9ab585fe) of Little Boy Plus, a BNB Chain DeFi mining protocol advertised as having 'no team, no pre-mine, no admin keys.' The LBPHashrate._update() function could be triggered by zero-value transferFrom calls, bypassing OpenZeppelin's allowance check. By calling transferFrom(pair, DEAD, 0) without authorization, the attacker triggered _harvest(pair), which minted LBP tokens directly to the PancakeSwap pair address via LBP.mintReward(pair, reward) — inflating the pair's token balance without updating its tracked reserve, creating a reserve imbalance exploitable via PancakePair.swap(). The attacker used large flash loans (34M USDT from PancakeSwap Infinity Vault and 7.7M USDT from Lista DAO: Moolah, both borrowed and repaid atomically) to amplify the attack, ultimately draining 377,642.57 USDT (~610.555 BNB) in a single transaction (0x55856d9fda4c5be5193561c7d775e823c3d6e499da44aab9da963daf61c50b0c, block 104727184). SlowMist published the TI Alert the same day with full address disclosure. On-chain tracing shows the final proceeds (~605.555 BNB, ~$354,656) were forwarded to wallet 0x51578879...6096F6D1A, with a smaller 5 BNB portion routed through a service labeled 'Puissant: Payment'. No public statement has been issued by the Little Boy Plus team and no recovery has been reported.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)