MOKE exploit on BNB Chain triggers about $907,700 loss

TenArmor flagged the incident after on-chain transfers involving MOKE, WBNB and PancakeSwap LP tokens, though the exact smart contract weakness remains unconfirmed.

BNB
WBNB
CAKE

Summary

A suspected exploit involving the MOKE token on BNB Chain led to an estimated $907,700 loss, with blockchain security firm TenArmor identifying the incident through an on-chain investigation. Transaction data shows large internal transfers tied to MOKE, Wrapped BNB (WBNB) and PancakeSwap liquidity pool (LP) tokens, including roughly 230,000 BNB that briefly moved through the WBNB contract before related transfers were executed. TenArmor said the attacker extracted 28.13 WBNB, worth about $16,400 at the time of the transaction, while the broader loss estimate was far higher. The exact attack path is still unclear because no technical post-mortem has been released, leaving open whether the issue stemmed from MOKE's smart contract, a liquidity management contract or another part of the protocol. The incident adds to a run of DeFi (decentralized finance) exploits on BNB Chain, where attackers have repeatedly targeted smart contracts and liquidity pools.

Terms & Concepts
  • WBNB: Wrapped BNB token used in smart contracts
  • liquidity pool (LP) tokens: Tokens representing a share of pooled assets
  • DeFi: Decentralized finance services built on blockchains