Skip to main content
6 min read

MOKE Exploit: $906.8K
Drained via Stale LP Dividend Records

$906.8K was extracted from MOKE after stale LP dividend records and same-block spot-price manipulation converted reserve MOKE into repeated BNB claims.

AUTOSEC.DEVAUTOSEC.DEV
MOKE Exploit: $906.8K Drained via Stale LP Dividend Records
  • Incident Date: August 2, 2026 at 20:50 UTC (August 3 at 04:50 UTC+8)
  • Target: MOKE
  • Target Overview: MOKE was a token ecosystem on BNB Chain with a primary MOKE/WBNB liquidity pool, a separate X/MOKE reserve pair, and an LP-dividend contract that converted MOKE into BNB for liquidity-provider rewards.
  • Total Loss: ~$906.8K in estimated net attacker profit; the affected MOKE/WBNB pair recorded a larger gross outflow of 1,692.745266 WBNB (~$995.9K)
  • Attacker: 0xe454a9bac1a44868e4a9cbe1a4b5ac231d0dcf8a
  • Attack Contract: 0xc7fdea027feb41c8f3a45ec284280ce68f4e6ff7
  • Affected Contracts: MOKE token 0x1A35C16cE21903Bc17Fd020c4ED73fEdC70c1b2A, LP-dividend pool 0x5ae569d8a0539a6A603E96A26ac8CaEA7CEba377, and release contract 0x684D722EbF8980f49492f631f56765DD4Fb302A7
  • Affected Network: BNB Chain
  • Attack Vector: Smart-contract logic flaw and oracle manipulation; flash loans supplied temporary capital but were not the root vulnerability

Incident Review & Technical Details

1. Attack Path

  1. One LP position was registered to many addresses: In preparation transaction 0xc0f1...6154, the attacker cycled the same 1,334.183807563777 MOKE/WBNB LP tokens through a series of helper addresses. Each address called syncUserLP() while temporarily holding the position, leaving a nonzero userLPRecord after the LP tokens moved onward.
  2. The accounting contract preserved claims for former holders: MokeLPDividend did not automatically clear a user's recorded LP balance when the LP tokens were transferred. During claimDividend(), the contract calculated pending rewards from the stale record before replacing it with the caller's current balance. This allowed every helper address to claim as if it still held the same LP position.
  3. Temporary liquidity distorted same-transaction price inputs: In the focal transaction 0x0776...6a8f, the attacker flash-borrowed 403,344.033277 WBNB and 3,169.548893 BTCB, then used BTCB as Venus collateral to borrow another 230,000 BNB. The attacker swapped a combined 633,344.033277 WBNB into 17,788,339.291766 USDT, changing the live DEX reserves consumed by MOKE's release path. The 230,000 BNB figure reported in early coverage was temporary attack capital, not the protocol's loss.
  4. The release path moved reserve MOKE into the dividend system: The attacker invoked the unverified release contract's settle() and claim() paths directly and through helper contracts. On-chain balance changes show the X/MOKE pair lost 43,860,308.980417 MOKE and the same amount of X. The MOKE token authorized the configured release contract to transfer tokens out of this reserve pair without an ordinary ERC-20 allowance.
  5. Reserve MOKE became claimable BNB: The released tokens were routed to MokeLPDividend, where distributeDividend() swapped 43,860,308.980417 MOKE for 1,664.616180024096 BNB. The attacker and helper addresses then called claimDividend(), producing repeated payouts of roughly 25.71278 BNB from the duplicated stale LP records.
  6. The attacker repaid the temporary liquidity and exited: After reversing the USDT trade and repaying Venus and the flash-loan providers, the focal transaction left the attacker with 1,546.442988 BNB while spending 2,989.298505 USDT. Using the transaction-time BNB price cited by Anomly, this yields approximately $906,810 in net profit. At 20:58 UTC, exit transaction 0xc34e...a3fd forwarded 1,546.537245 BNB through PancakeSwap's SmartRouter to 0x6254...50ff.

2. Impact Scope

  • Protocol-Level Loss: The best available transaction-level accounting estimates the attacker's net profit at ~$906.8K. This is consistent with TenArmor's early $907.7K alert after allowing for valuation and rounding differences.
  • Liquidity-Pool Outflow: The MOKE/WBNB pair lost 1,692.745266 WBNB (~$995.9K gross) during the focal transaction. The difference between gross pool outflow and net attacker profit reflects the WBNB/USDT round trip, the attacker's USDT expenditure, and transaction costs.
  • Reserve and Accounting Exposure: Approximately 43.86 million MOKE left the X/MOKE reserve path and funded the BNB dividend distribution. The exploit therefore combined two weaknesses: same-block reserve-dependent release logic and stale ownership records in the dividend contract.
  • External Protocols: Venus, PancakeSwap, and the flash-loan sources supplied composable liquidity or execution venues, but the reviewed evidence does not indicate losses or contract compromises at those protocols.
  • User and Recovery Status: No verified MOKE incident statement, contract-pause notice, reimbursement plan, or recovery announcement was located as of August 10, 2026 [NEEDS VERIFICATION].

3. Official Statements

  • MOKE: No official disclosure or post-mortem was located in the reviewed sources as of August 10, 2026. Whether the affected release and dividend paths were disabled or patched remains [NEEDS VERIFICATION].
  • TenArmor: In its August 3 alert, TenArmor identified a suspicious MOKE transaction on BNB Chain and estimated the loss at approximately $907.7K. The alert did not provide a root-cause analysis.
  • Blokiments: On August 9, Blokiments attributed the incident to same-transaction spot-price settlement and stale LP-dividend records, citing the subsequent Anomly transaction analysis.

4. Investigation Progress

The preparation, focal, and exit transactions are all identifiable on-chain. Verified MOKE and MokeLPDividend source code supports the stale-record finding, while call traces and balance changes show the release contract moving reserve MOKE into the dividend pool. However, the release contract at 0x684D...02A7 has no verified source code, so its exact internal price and settlement logic remains only partially reconstructable from on-chain behavior [NEEDS VERIFICATION].

Blokiments traced the exit proceeds from 0x6254...50ff through 0xF38B...8213 and 0x8d9d...EA1C, then to 0x8f01...5C25 on August 5. It reported that the final address was converting BNB into Binance-Peg BSC-USD and still held the traced funds on August 9. No reviewed source confirms a freeze, return, mixer deposit, exchange seizure, attacker negotiation, or law-enforcement action as of August 10, 2026 [NEEDS VERIFICATION].


AUTOSEC.DEV Solution

Preventing this failure mode requires treating LP ownership accounting, privileged reserve-release authority, and price inputs as one adversarially composable system.

  1. Secure Code Review — AUTOSEC.DEV would test the exact state transition that failed at MOKE: moving one LP position between addresses after syncUserLP() and then claiming against a stale record. The review also traces every privileged path behind releaseFromPair(), verifies that rewards accrue only to current ownership, and checks that records are updated before any value is credited or transferred.
  2. Security Strategy & Planning — MOKE's release and dividend mechanisms allowed a same-transaction reserve distortion to become a pool-wide BNB payout. AUTOSEC.DEV helps protocols replace raw spot-reserve dependencies with manipulation-resistant pricing, cap per-block releases and dividend distributions, and define circuit breakers for abnormal reserve movement or repeated claims from related addresses.
  3. Penetration Testing — A realistic MOKE test must compose flash liquidity, reserve manipulation, LP-token transfers, helper contracts, and EIP-7702 delegated execution in one scenario. AUTOSEC.DEV builds these transaction-shaped tests against staging or a forked deployment to verify that economic invariants survive adversarial ordering, not just ordinary user flows.

Reference