Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Telegram Ban India Crypto, TON & Durov's Attack on Reliance
    Telegram Ban in India: Crypto, TON & Durov’s Attack on Reliance
    Hormuz Peace Dividend How the US-Iran Deal Fuels Dubai RWAs & Not Tehran
    Hormuz Peace Dividend: How the US-Iran Deal Fuels Dubai RWAs & Not Tehran
    Kevin Warsh's First FOMC What It Means for Bitcoin and Crypto
    Bitcoin and the ‘Fed Chair Curse’: What Kevin Warsh’s First FOMC Means for Crypto
    Crypto Tax Overhaul What Congress’s New Framework Means for 60M Americans
    Crypto Tax Overhaul: What Congress’s New Framework Means for 60M Americans
    One Laptop, $36 Million, and a Token Collapse Inside the Humanity Protocol Exploit
    Humanity Protocol $36M Exploit: 447M $H Hit After Laptop Breach and Multisig Failure
  • Opinion
    OpinionShow More
    The Arthur Hayes Paradox Macro Prophet or Market Opportunist
    The Arthur Hayes Paradox: Macro Prophet or Market Opportunist?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India's Digital Rupee Push?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India’s Digital Rupee Push?
    The CLARITY Act War Starts Jamie Dimon Vs Armstrong
    The CLARITY Act War Starts: Jamie Dimon Vs Armstrong
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino?
    CoinSwitch on TMKOC India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It_
    CoinSwitch on TMKOC: India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Little Boy Plus Loses $377K as “No-Admin-Key” DeFi Protocol Gets Drained via Mint Bug

The freshly minted tokens skewed the pair's balance against its reserve, letting the attacker swap the pool's USDT out.

Written By:
Dhara Chavda

Last updated: 45 minutes ago
Published 1 hour ago
Share
Little Boy Plus Loses $377K After Exploit Targets Minting Bug
Show AI Summary
Little Boy Plus protocol was exploited by an attacker who minted tokens without admin keys.
SlowMist identified the vulnerability in the LBPHashrate._update() function, allowing unauthorized minting.
The attacker, identified as 0x5449ded887576f43fc339851e942ebc1e6f8118b, drained approximately $377,000 from the protocol.

Little Boy Plus, a BNB Chain mining protocol that advertised no team and no admin keys, was drained of about $377,000 after a logic flaw let an attacker mint its token out of thin air — no stolen key required.

A protocol built to need no trust

Little Boy Plus markets itself as a fully decentralized DeFi mining protocol on BNB Smart Chain, with a fixed supply of 21,000,000 LBP and, in its own words, no team, no pre-mine, and no admin keys. The entire pitch rests on the idea that no privileged party can inflate the token’s supply.

The exploit cut straight through that promise. According to SlowMist, the attacker minted fresh LBP without holding any admin key or compromising a private wallet — the unauthorized mint was reachable through ordinary public contract calls.

🚨SlowMist TI Alert🚨

💸 @LittleBoyPlus has been exploited. Loss: ~377,642 USDT (~610.555 BNB)

🔍 Root Cause: The `LBPHashrate._update()` function (in `0x5e3c…85fe`) is triggered by zero-value `transferFrom` calls, which bypasses OpenZeppelin's allowance check. This allows an…

— SlowMist (@SlowMist_Team) June 18, 2026

How the zero-value transfer bug worked

SlowMist traced the flaw to the LBPHashrate._update() function in the contract at 0x5e3c...585fe, which it said is triggered by zero-value transferFrom calls that bypass OpenZeppelin’s allowance check. That let the attacker call LBPHashrate.transferFrom(pair, DEAD, 0) without the pair’s authorization.

That call triggered _harvest(pair), which minted LBP straight to the PancakePair address via LBP.mintReward(pair, reward). The minted tokens raised the pair’s LBP balance but not its tracked reserve — and that imbalance let the attacker drain the pool’s USDT through PancakePair.swap().

The addresses and the open questions

SlowMist identified the attacker as 0x5449ded887576f43fc339851e942ebc1e6f8118b, the victim pair as 0x00e3ea08fd8cbad955ec5d2292ad637670c31524, and the vulnerable LBPHashrate contract as 0x5e3cbc82d020be91a989eb747934104e9ab585fe, pinning the loss at roughly 377,642 USDT (~610.555 BNB).

As of publication, the Little Boy Plus Foundation had not issued a public statement on the incident, and there was no word on whether any of the drained funds could be recovered.

The latest in a run of BSC reward-logic drains

The attack fits a pattern that has accelerated across BNB Chain through 2026. Just a day earlier, SlowMist flagged the DIP token drain of about $111K, where a transfer bug let skim() double-drain reserves and rewrite an AMM pair’s price, the same structural class of a token’s own logic being coaxed into skewing a PancakeSwap pool.

In February, SOF and LAXO were drained for $438K combined when flash loans turned tiny mining-reward emissions into reserve imbalances. Earlier this month, the ATM token lost about $243K to a transferFrom branch that quietly swapped out extra BSC-USD on each transfer.

The through-line is consistent: small BSC mining and reward tokens keep failing when custom transfer or emission logic can be manipulated to skew PancakeSwap reserves, a class of bug that no amount of “no admin keys” branding can prevent.

Also Read: TesseraDAO TSR Token Crashes 99% Following 99M Token Mint Exploit

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Blockchain
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Dhara Chavda- Crypto Research Analyst at The Crypto Times
By Dhara Chavda
Follow:
Dhara Chavda is a Content Strategist and Research Analyst with 5 years of experience in the crypto industry. She holds a Bachelor’s degree in Computer Engineering and brings a strong technical perspective to her work. Dhara specializes in DeFi, price analysis, and the core mechanics of cryptocurrencies. She also works on crypto news, including research, analysis, and assigning stories, ensuring accurate and timely coverage of key developments in the space.

Latest News

Kentucky Sues Kalshi and Polymarket As Prediction Market Wars Escalates
Kentucky Sues Kalshi and Polymarket As Prediction Market Wars Escalates
Aztec Network’s RollupProcessor Exploited for $2.21 Million
Aztec Network’s RollupProcessor Exploited for $2.21 Million 
OKX’s Star Xu Slams Binance, Says Compliance Dodging Is Over
OKX’s Star Xu Slams Binance, Says Compliance Dodging Is Over
Bitcoin Dips, Altcoins Plunge: Full Impact of June 2026 FOMC Meeting on Crypto
Bitcoin Dips, Altcoins Plunge: Full Impact of June 2026 FOMC Meeting on Crypto
CME to Sue CFTC Over Kalshi’s Bitcoin Perpetual Futures
CME to Sue CFTC Over Kalshi’s Bitcoin Perpetual Futures

Find Us on Socials

You may also like

UXLINK Exploiter Moves 8,340 ETH—Then Sends It to Tornado Cash

UXLINK Exploiter Moves 8,340 ETH—Then Sends It to Tornado Cash

DeFi Tokens Are Shifting From Hype to Hard Numbers Grayscale

DeFi Tokens Are Shifting From Hype to Hard Numbers: Grayscale

Zama Brings Confidential USDC Yield to Ethereum with Morpho

Zama Brings Confidential USDC Yield to Ethereum with Morpho

Humanity Starts H Token Airdrop After $36M Exploit Fallout

Humanity Starts H Token Airdrop After $36M Exploit Fallout

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information