Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

Cyprus Police Probe Two Crypto Scams After €75,000 Losses

June 6, 2026

Meta is paying creators in Stablecoins. Spending them is someone else's problem

June 6, 2026

Billionaire Stanley Druckenmiller Pours $68,150,000 Into Four Stocks That Have Each Exploded 200%+ Year-to-Date

June 6, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»$243,500 Drained via Hidden Swap Loophole
Security

$243,500 Drained via Hidden Swap Loophole

June 6, 2026No Comments3 Mins Read

A relatively obscure token called ATM, deployed on the $BNB Smart Chain (BSC), became the latest victim of a smart contract vulnerability. An attacker drained approximately $243,500 by exploiting non-standard logic in the token’s transferFrom() function.

Security monitoring platforms TenArmor flagged the incident on June 4, 2026. The alerts highlighted how custom token mechanics, often added for fees, liquidity provision, or rewards, can create serious exploitable weaknesses when not properly secured.

#CertiKInsight

We have seen an exploit of ~$243K on ATM token. The transferFrom() includes logic to swap 20% transfer amount of ATM for BSC-USD, so the attacker can repeatedly swap out extra after transfer.https://t.co/mf6uhujZgK

Stay vigilant! pic.twitter.com/hwN1B3Xt0m

— CertiK Alert (@CertiKAlert) June 4, 2026

According to CertiK’s analysis, the core issue lay in the token contract’s transferFrom() implementation. Instead of performing a standard token transfer, the function automatically triggered a swap of 20% of the transferred ATM amount into BSC-USD (or equivalent) through a decentralized exchange router.

This hidden behavior allowed the attacker to repeatedly initiate transfers that extracted far more value than normal approvals should permit. The main attack transaction hash is: 0x37b90a…dcfd86

Contract Address: 0x4fd087…d5a205

Blockchain security alerts detected the suspicious activity at an early stage. The attacker’s address, 0x7e7C1f…CdBAFE, has been associated with previous token contract exploits since 2025. The attack did not rely on flash loans or reentrancy but leveraged the unintended economic side effects of the custom transfer logic.

This latest incident adds to a worrying wave of exploits on $BNB Chain. Just days earlier, TesseraDAO was hit in a major attack where the exploiter minted roughly 99 million TSR tokens, dumped them, and drained around $2.5 million in USDT. The TSR token crashed nearly 99% following the incident.

See also  China Confirms Participation in 'First of Its Kind' Anti-Pig Butchering Operation

Public information about the ATM project remains very sparse. There is no widely available official website, whitepaper, or detailed roadmap. The project does not appear to be a major DeFi protocol, and details regarding its intended use case, team background, or total value locked (TVL) before the exploit are not well documented.

As of June 5, 2026, the ATM project team has not issued any official public statement regarding the incident, whether the contract was paused, liquidity status, or any recovery efforts.

Such vulnerabilities are not isolated. In late May 2026, attackers exploited legacy liquidity lockers on DxSale and drained approximately $7.3 million from over 1,400 pools by manipulating unlock timestamps and withdrawing LP tokens. This shows how even older “locked” liquidity from previous cycles can remain at risk.

This incident serves as a classic example of the dangers associated with custom tax-on-transfer or auto-swap mechanisms in ERC-20-like contracts. While such features can serve legitimate purposes, they significantly increase complexity and the attack surface.

Blockchain security experts consistently warn that combining transferFrom() with external calls, such as to DEX routers, requires rigorous auditing, formal verification, and extensive edge-case testing.

  • Always verify smart contracts thoroughly before interacting with them.
  • Revoke token approvals regularly, especially for unknown or low-cap tokens.
  • Prefer projects with multiple independent audits and transparent security practices.

Even though this is a mid-sized exploit by 2026 standards, such incidents continue to erode confidence in the broader DeFi ecosystem. Smaller tokens on chains like $BNB Smart Chain remain frequent targets due to rushed deployments and insufficient security measures.

See also  How to Use Your Digital Wallet Effectively

Users are strongly advised to exercise extreme caution when dealing with new or low-visibility tokens.



Source link

drained Hidden Loophole Swap

Related Posts

Cyprus Police Probe Two Crypto Scams After €75,000 Losses

June 6, 2026

Saskatoon Man Faces US Extradition on Crypto Hacking Charges

June 6, 2026

THORChain restart drags on as Zcash vulnerability delays privacy-coin rollout

June 6, 2026

Arthur Hayes dumps zcash holdings after Orchard Pool vulnerability revealed

June 6, 2026
Top Posts

TaskOn Partners with Fortune Global to Accelerate Liquidity Infrastructure for Prediction Markets

May 14, 2026

Asseto Finance Achieves Regulatory Milestone for RWA Tokenization in Hong Kong

March 8, 2026

FTX: Over $400m Was Stolen from Bankrupt Exchange

October 12, 2023

Type above and press Enter to search. Press Esc to cancel.