← Radar

Incident case file

Sign in to watch

MOKE Token Unprotected claim() Function Exploit

Incident date 2026-08-01Last updated Aug 14, 2026

2 views

ActiveBNB ChainSmart contract vulnerability (access control)Cluster: MOKE-SC-2026-08

Estimated loss

$907.7K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

25%

Facts and investigation

Ledger

Attacker

MISSING — no exploit transaction or attacker address has been independently verified on-chain despite four separate manual investigation attempts (see timeline notes below).

Funds moved to

MISSING — SlowMist Hacked and TenArmor report that approximately 166 million MOKE tokens were drained via a combination of flash loans, Venus Protocol leverage, LP removal, and dividend distribution mechanisms, ultimately converted into approximately 1,546 BNB. No specific exploit transaction hash or attacker-controlled wallet address has been independently confirmed on-chain in this investigation. An initially suspected transaction (0x3c02720c0ded5d51386ecf253a5387f2ee2624ada73d2514bcc16a87bb

Linked

MOKE token contract address: 0x273b54cBAE81fC75193C1352f0b3667960f1F1B8. The exploit reportedly involved the MokeToken.releaseContract() function and interactions with PancakeSwap V2 MOKE-BSC-USD liquidity pools alongside the Venus lending protocol. No official MOKE project team post-mortem has been published as of the reporting window's close. Multiple manual verification attempts using BscScan's Advanced Filter tool (searching amount ranges above 1,000,000 MOKE within the August 2-3, 2026 date

Chronology

1 beat
  1. August 2, 2026: The MOKE token protocol on BNB Chain is exploited. Per SlowMist Hacked's official incident record: 'The attacker abused an unprotected public claim() function in MokeToken.releaseContract() (no eligibility check on the caller), repeatedly draining ~166 million MOKE from the protocol's internal reserve pool, then used flash loans, Venus leverage, LP removal, and dividend distribution mechanisms to convert it into ~1,546 BNB, resulting in a loss of approximately $907,700.' August 3, 2026, 02:23:58 UTC: Security firm TenArmor publishes the first public alert via its automated on-chain monitoring system (TenMonitor), confirming the estimated $907.7K loss figure and noting the exploit connects to PancakeSwap V2 liquidity pools and the MokeLPManager contract, with LP tokens being moved and subsequently burned; TenArmor explicitly states it had not, at time of alert, released a full technical breakdown identifying the specific attacker address. CryptoTimes, reporting the same day, notes that the exploit transaction it examined displayed an 'execution reverted' message during processing, though portions of the transaction nonetheless resulted in successful token movements — leaving the precise root-cause mechanism (whether located in the token contract itself, a liquidity management contract, or elsewhere in the protocol) formally unconfirmed by any published post-mortem. Subsequent investigation notes (August 8, 2026): manual attempts to locate the specific exploit transaction and definitively identify the attacker's wallet address were unsuccessful across four distinct methodological approaches, including use of BscScan's Advanced Filter tool — a technique that successfully isolated comparable single-transaction 'Sweep' events for other incidents investigated in the same reporting window (Panther Protocol and StrongBlock), but which returned no matching large-value MOKE transaction within the August 2-3 window when filtered by amount. This strongly suggests the MOKE token drain, unlike the single-sweep exploits documented elsewhere this week, was likely executed via numerous smaller, repeated calls to the vulnerable claim() function rather than one traceable large transaction — a distribution pattern that resists straightforward on-chain filtering techniques. As of the close of the reporting window, no attacker wallet address, specific exploit transaction hash, or official statement from the MOKE project team has been publicly identified or independently verified on-chain.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)