Incident case file
Sign in to watchMOKE Token Unprotected claim() Function Exploit
2 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatAugust 2, 2026: The MOKE token protocol on BNB Chain is exploited. Per SlowMist Hacked's official incident record: 'The attacker abused an unprotected public claim() function in MokeToken.releaseContract() (no eligibility check on the caller), repeatedly draining ~166 million MOKE from the protocol's internal reserve pool, then used flash loans, Venus leverage, LP removal, and dividend distribution mechanisms to convert it into ~1,546 BNB, resulting in a loss of approximately $907,700.' August 3, 2026, 02:23:58 UTC: Security firm TenArmor publishes the first public alert via its automated on-chain monitoring system (TenMonitor), confirming the estimated $907.7K loss figure and noting the exploit connects to PancakeSwap V2 liquidity pools and the MokeLPManager contract, with LP tokens being moved and subsequently burned; TenArmor explicitly states it had not, at time of alert, released a full technical breakdown identifying the specific attacker address. CryptoTimes, reporting the same day, notes that the exploit transaction it examined displayed an 'execution reverted' message during processing, though portions of the transaction nonetheless resulted in successful token movements — leaving the precise root-cause mechanism (whether located in the token contract itself, a liquidity management contract, or elsewhere in the protocol) formally unconfirmed by any published post-mortem. Subsequent investigation notes (August 8, 2026): manual attempts to locate the specific exploit transaction and definitively identify the attacker's wallet address were unsuccessful across four distinct methodological approaches, including use of BscScan's Advanced Filter tool — a technique that successfully isolated comparable single-transaction 'Sweep' events for other incidents investigated in the same reporting window (Panther Protocol and StrongBlock), but which returned no matching large-value MOKE transaction within the August 2-3 window when filtered by amount. This strongly suggests the MOKE token drain, unlike the single-sweep exploits documented elsewhere this week, was likely executed via numerous smaller, repeated calls to the vulnerable claim() function rather than one traceable large transaction — a distribution pattern that resists straightforward on-chain filtering techniques. As of the close of the reporting window, no attacker wallet address, specific exploit transaction hash, or official statement from the MOKE project team has been publicly identified or independently verified on-chain.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)