
A significant cryptocurrency exploit has resulted in the loss of 396.43 Binance BNB tokens worth approximately $226,000 from the BFB token's price-defense mechanism. According to reports from AMBCrypto, the attack targeted a logical flaw in BFB's price-defense mechanism on BNB Chain rather than the PancakeSwap liquidity pool itself. The exploit involved an attacker using zero-value transferFrom() calls to trigger the _priceDeflPool() function with a flash loan, causing the contract to burn 5% of BFB tokens stored in the PancakeSwap liquidity pool approximately 151 times.
The attacker first funded gas fees using assets routed through Railgun, a privacy protocol that obscures transaction origins. As reported by AMBCrypto, after the BFB reserve was nearly exhausted, the attacker consumed the stolen BNB by exchanging a small amount of BFB for nearly all the BNB in the pool. The stolen BFB was later converted into BNB and left in wallet 0x3BFA...6b0F without moving the funds. The attacker combined multiple techniques including liquidity pool draining, reserve manipulation, Automated Market Maker (AMM) price manipulation, flash loans, logic exploitation, zero-value transaction abuse, repeated execution, and Railgun funding.
This attack coincided with TRM Labs data revealing a record 207 security breaches in the first half of 2026. According to AMBCrypto, despite the increase in breaches, total losses fell sharply to $972 million, less than half the $2.3 billion stolen during the same period in 2025. The exploit follows recent security incidents including Polymarket's phishing incident where attackers compromised the frontend and manipulated what users viewed and signed, and Summer.fi's post-mortem showing attackers spent about three months preparing the $6.04 million Lazy Summer Protocol exploit before execution.