Incident case file
Sign in to watchSKP — Token LP-Balance Drain + sync() Reserve Manipulation (Flash-Loan Amplified)
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: Exploiter 1 (trigger EOA): 0x83B9e7EDC5B3127E4853A4F4945b92aa88eEF0C8. Exploiter 2 (attack contract): 0xE924853DcDfcB89292335042AB10d68c7315D7C1.
Timeline: On 27 May 2026, in a single transaction (0xbc01ea37...f25ee, BSC block 100582079), an attacker drained ~$212,850 (162,854.21 USDT + ~74.877 BNB) from the SKP/USDT market on PancakeSwap V2. The SKP token logic allowed extra SKP to be transferred out of the LP after a large buy; the attacker then called sync() to write incorrect reserves, pushing SKP reserves toward zero and letting USDT be extracted. The attack was amplified with flash loans from Lista DAO Moolah (BTCB and USDT) and a Venus borrow (~88M USDT against vBTC collateral). A two-contract structure was used: a trigger EOA (0x83B9e7ED...eF0C8) drove an attack contract (0xE924853D...5D7C1), which paid 1 BNB to BlockRazor for a MEV bundle and returned the net profit to the EOA. TenArmor detected and publicised the attack the same day (~$212K). Recovery: 0%. (BscScan displays transient values in the hundreds of millions for BTCB/USDT inside the transaction; these are flash-loaned amounts in transit and not the realised loss.)
Sources and coverage
- Articlehacked.slowmist.iohttps://hacked.slowmist.io/
- Articlecryptotimes.iohttps://www.cryptotimes.io/2026/05/27/skp-liquidity-exploit-drains-212k-across-bnb-chain-defi-protocols/
- Articlex.comhttps://x.com/TenArmorAlert/status/2059454844201562191
- Articlebscscan.comhttps://bscscan.com/tx/0xbc01ea37bd2ff8f6aa6afcfbe0406114ff27a01e9aa56102bfa4ad8a0c2f25ee
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)