A suspected exploit on the BNB Chain for the MOKE token caused an approximately $907,700 loss. On-chain data shows the attacker carried out a series of transactions involving liquidity pool contracts and Wrapped BNB (WBNB), although the exact vulnerability behind the exploit remains unknown.
TenArmor, a blockchain security firm, recently identified the exploit and produced an alert based on the on-chain investigation for MOKE. The firm has not yet released a technical analysis explaining how the attack was carried out or identifying the attacker.
Significant token movements
Blockchain data from the attack transaction shows a series of large internal transfers involving MOKE, Wrapped BNB (WBNB), and PancakeSwap liquidity pool (LP) tokens. The transaction indicates that approximately 230,000 BNB briefly moved through the WBNB contract before associated transfers involving PancakeSwap LP tokens and MOKE were executed.
According to market data from Bitget Wallet, MOKE was trading at around $0.00076 at the time of writing. TenArmor estimated the total loss to be about $907,700, while the attacker took 28.13 WBNB, worth about $16,400 at the time of the transaction.
The transaction also displays an execution reverted message during execution of the contract, but parts of the transaction were still processed, resulting in successful token movements.
Investigation ongoing
According to on-chain data, the exploit connected to a few PancakeSwap V2 liquidity pools and the MokeLPManager contract. LP tokens were moved and burned. The MOKE tokens and WBNB went through a number of contracts before the transaction was completed.
Without a public post-mortem from the MOKE team, the exact mechanism of the exploit cannot be confirmed. Therefore, it is not known whether the loss was from the token’s smart contract, a liquidity management contract, or any other part of the protocol.
The hack is the latest in a string of DeFi exploits on BNB Chain, where hackers keep exploiting smart contracts and liquidity pools to steal funds.
At the time of writing, neither the MOKE team nor TenArmor had shared more technical details or any updates on recovering the stolen funds. More information is expected as the investigation into the exploit continues.
Also Read: $4B Iran Crypto Operation Exposed Through Dubai Exchange
