QooryBeta
Back to narratives
SecurityActive
Conversation intelligence

AIDC Token on BSC Exploited for $121K

The AIDC token on BSC was exploited due to a flaw in the _sellTransfer() function, resulting in a loss of 220.12 WBNB (~$120,929). The attacker manipulated the burn mechanism to drain WBNB from the liquidity pool.

Heat
97
Confidence
95%
Evidence
8
Updated

Why It Happened

The root cause is a logic error in AIDCToken's _sellTransfer() which accumulates a 30% burn amount without deducting it from the seller. Any non-Pair transfer then triggers _executeAccumulatedBurn(), which incorrectly burns tokens from the uniswapPair balance and calls sync(), artificially deflating the AMM reserve and allowing the attacker to drain WBNB.

Outcome So Far

The attacker address 0x89eb2c99e970d831525c7a52badc290afa116b63 has been identified. The total loss is approximately $121,000. No further recovery actions have been reported.

Actors

Timeline order

Post
Parent event 01

🔥Glad to support @HTX_DAO’s HTX Genesis Hackathon as a security partner! Hosted by HTX DAO & h…

🔥Glad to support @HTX_DAO’s HTX Genesis Hackathon as a security partner! Hosted by HTX DAO & https://t.co/lHXau7APFb, this global hackathon focuses on AI × Web3 innovations in smart finance, AI Agents, and on-chain infrastructure. $20,000 prize pool + $100k …

Related posts@SlowMist_Team
@SlowMist_Team
Open on X9.9K views · 21 likes · 3 reposts

Post
Parent event 02

Android 17 root Full chain browser-to-kernel exploit with two 0-day vulnerabilities affecting F…

Android 17 root Full chain browser-to-kernel exploit with two 0-day vulnerabilities affecting Firefox before v151.0.2 (CVE-2026-10702) Click on the link -> root Android Discovered by @nebusecurity PoC not available. Info: https://t.co/1dmlWIsuyR https://t.…

Related posts@androidmalware2@immunefi@SlowMist_Team
@androidmalware2
Open on X49.2K views · 563 likes · 76 reposts
@immunefi
Open on X11.7K views · 250 likes · 26 reposts
@SlowMist_Team
Open on X9.2K views · 9 likes · 1 reposts

Post
Parent event 03

🚨 SlowMist TI Alert 🚨 The Mini Shai-Hulud, Miasma, and Hades malware family, now expanding be…

🚨 SlowMist TI Alert 🚨 The Mini Shai-Hulud, Miasma, and Hades malware family, now expanding beyond npm into the Go module ecosystem. Affected Go modules: https://t.co/nPz4NKSFLJ https://t.co/3HDcGaliRT https://t.co/wFHylBXyjG is a Cosmos SDK-based Layer 1 bl…

Related posts@SlowMist_Team
@SlowMist_Team
Open on X4.2K views · 10 likes · 0 reposts

Post
Parent event 04

SlowMist TI Alert: AIDC Token Exploit

SlowMist_Team reported that the AIDC token on BSC was exploited due to a flaw in _sellTransfer(), with a loss of 220.12 WBNB (~$120,929). The root cause and attacker address were disclosed.

Related posts@SlowMist_Team@Robobby1
@SlowMist_Team
Open on X15.0K views · 91 likes · 25 reposts
@Robobby1
Open on X567 views · 12 likes · 4 reposts

Post
Parent event 05

X conversation update

1 related posts from @wublockchain12

Related posts@wublockchain12
@wublockchain12
Open on X3.5K views · 2 likes · 0 reposts