• bitcoinBitcoin (BTC) $ 60,534.00
  • ethereumEthereum (ETH) $ 1,555.92
  • tetherTether (USDT) $ 0.999543
  • bnbBNB (BNB) $ 572.51
  • usd-coinUSDC (USDC) $ 0.999746
  • xrpXRP (XRP) $ 1.08
  • solanaSolana (SOL) $ 61.62
  • tronTRON (TRX) $ 0.323072
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • dogecoinDogecoin (DOGE) $ 0.081249
  • hyperliquidHyperliquid (HYPE) $ 56.22
  • usdsUSDS (USDS) $ 0.999737
  • leo-tokenLEO Token (LEO) $ 9.47
  • rainRain (RAIN) $ 0.012820
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • stellarStellar (XLM) $ 0.210087
  • canton-networkCanton (CC) $ 0.161900
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • zcashZcash (ZEC) $ 352.08
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • cardanoCardano (ADA) $ 0.156442
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • moneroMonero (XMR) $ 293.81
  • chainlinkChainlink (LINK) $ 7.36
  • whitebitWhiteBIT Coin (WBT) $ 43.03
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • usd1-wlfiUSD1 (USD1) $ 0.998907
  • ethena-usdeEthena USDe (USDE) $ 0.999533
  • susdssUSDS (SUSDS) $ 1.08
  • the-open-networkToncoin (TON) $ 1.65
  • bitcoin-cashBitcoin Cash (BCH) $ 215.24
  • labLAB (LAB) $ 13.43
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • daiDai (DAI) $ 0.999757
  • memecoreMemeCore (M) $ 3.02
  • hedera-hashgraphHedera (HBAR) $ 0.079345
  • wethWETH (WETH) $ 2,268.37
  • litecoinLitecoin (LTC) $ 40.98
  • suiSui (SUI) $ 0.711241
  • avalanche-2Avalanche (AVAX) $ 6.62
  • usdt0USDT0 (USDT0) $ 0.998824
  • paypal-usdPayPal USD (PYUSD) $ 1.00
  • hashnote-usycCircle USYC (USYC) $ 1.13
  • shiba-inuShiba Inu (SHIB) $ 0.000005
  • tether-goldTether Gold (XAUT) $ 4,284.56
  • crypto-com-chainCronos (CRO) $ 0.058095
  • global-dollarGlobal Dollar (USDG) $ 1.00
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • nearNEAR Protocol (NEAR) $ 1.86
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.12
  • pax-goldPAX Gold (PAXG) $ 4,291.19
  • bittensorBittensor (TAO) $ 192.69
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.055380
  • mantleMantle (MNT) $ 0.513528
  • ripple-usdRipple USD (RLUSD) $ 0.999940
  • aster-2Aster (ASTER) $ 0.618426
  • polkadotPolkadot (DOT) $ 0.934946
  • ondo-financeOndo (ONDO) $ 0.322859
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • htx-daoHTX DAO (HTX) $ 0.000002
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • uniswapUniswap (UNI) $ 2.44
  • falcon-financeFalcon USD (USDF) $ 0.996175
  • okbOKB (OKB) $ 68.76
  • worldcoin-wldWorldcoin (WLD) $ 0.417688
  • usddUSDD (USDD) $ 0.999667
  • pi-networkPi Network (PI) $ 0.123970
  • bfusdBFUSD (BFUSD) $ 0.999301
  • skySky (SKY) $ 0.055332
  • bitget-tokenBitget Token (BGB) $ 1.83
  • internet-computerInternet Computer (ICP) $ 2.29
  • pepePepe (PEPE) $ 0.000003
  • humanityHumanity (H) $ 0.608805
  • morphoMorpho (MORPHO) $ 1.64
  • ethereum-classicEthereum Classic (ETC) $ 6.74
  • usdtbUSDtb (USDTB) $ 1.00
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • united-stablesUnited Stables (U) $ 0.999899
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.21
  • blockchain-capitalBlockchain Capital (BCAP) $ 107.06
  • quant-networkQuant (QNT) $ 66.59
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.10
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • dexeDeXe (DEXE) $ 19.98
  • aaveAave (AAVE) $ 60.24
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.11
  • kaspaKaspa (KAS) $ 0.030376
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • ethenaEthena (ENA) $ 0.089487
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • cosmosCosmos Hub (ATOM) $ 1.62
  • render-tokenRender (RENDER) $ 1.59
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • algorandAlgorand (ALGO) $ 0.092003
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.076945
  • wbnbWrapped BNB (WBNB) $ 759.61
  • kucoin-sharesKuCoin (KCS) $ 6.08
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.797391
  • stable-2​​Stable (STABLE) $ 0.032865
  • nexoNEXO (NEXO) $ 0.742803
  • venice-tokenVenice Token (VVV) $ 15.38
  • justJUST (JST) $ 0.082869
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • audieraAudiera (BEAT) $ 2.27
  • gatechain-tokenGate (GT) $ 6.13
  • beldexBeldex (BDX) $ 0.078468
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • siren-2Siren (SIREN) $ 0.831490
  • xdce-crowd-saleXDC Network (XDC) $ 0.029476
  • ghoGHO (GHO) $ 0.999219
  • flare-networksFlare (FLR) $ 0.006706
  • filecoinFilecoin (FIL) $ 0.725073
  • usual-usdUsual USD (USD0) $ 0.998515
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • aptosAptos (APT) $ 0.651156
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • yldsYLDS (YLDS) $ 0.999618
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • midnight-3Midnight (NIGHT) $ 0.030888
  • a7a5A7A5 (A7A5) $ 0.013063
  • hash-2Provenance Blockchain (HASH) $ 0.009470
  • clbtcclBTC (CLBTC) $ 76,920.00
  • injective-protocolInjective (INJ) $ 5.08
  • jupiter-exchange-solanaJupiter (JUP) $ 0.152347
  • ousgOUSG (OUSG) $ 115.47
  • arbitrumArbitrum (ARB) $ 0.079120
  • true-usdTrueUSD (TUSD) $ 0.998517
  • pump-funPump.fun (PUMP) $ 0.001407
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • usxUSX (USX) $ 0.999686
  • spiko-amundi-overnight-swap-fund-eurSpiko Amundi Overnight Swap Fund (EUR) (EURSAFO) $ 1.16
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.196476
  • tbtctBTC (TBTC) $ 70,942.00
  • euro-coinEURC (EURC) $ 1.15
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.04
  • kite-2Kite (KITE) $ 0.182554
  • vechainVeChain (VET) $ 0.004706
  • dashDash (DASH) $ 31.73
  • apxusdapxUSD (APXUSD) $ 0.929782
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.006237
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.20
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • adi-tokenADI (ADI) $ 3.70
  • hastra-primePRIME (PRIME) $ 1.04
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • official-trumpOfficial Trump (TRUMP) $ 1.57
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • the9bitThe9bit (9BIT) $ 0.045232
  • cocaCOCA (COCA) $ 1.30
  • bonkBonk (BONK) $ 0.000004
  • lighterLighter (LIT) $ 1.42
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.539556
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • skyaiSkyAI (SKYAI) $ 0.346206
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997125
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000061
  • sun-tokenSun Token (SUN) $ 0.017349
  • blockstackStacks (STX) $ 0.179424
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • sei-networkSei (SEI) $ 0.046541
  • aerodrome-financeAerodrome Finance (AERO) $ 0.315193
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • kinesis-goldKinesis Gold (KAU) $ 121.47
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • ethgas-2ETHGas (GWEI) $ 0.136829
  • unibaseUnibase (UB) $ 0.111019
  • curve-dao-tokenCurve DAO (CRV) $ 0.182388
  • celestiaCelestia (TIA) $ 0.299247
  • fraxLegacy Frax Dollar (FRAX) $ 0.997057
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • spx6900SPX6900 (SPX) $ 0.293587
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • usdgoUSDGO (USDGO) $ 0.999782
  • tezosTezos (XTZ) $ 0.243146
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • apenftAINFT (NFT) $ 0.00000027
  • bittorrentBitTorrent (BTT) $ 0.00000027
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • olympusOlympus (OHM) $ 17.37
  • zebec-networkZebec Network (ZBCN) $ 0.002629
  • chilizChiliz (CHZ) $ 0.024806
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • ether-fiEther.fi (ETHFI) $ 0.286429
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • kinesis-silverKinesis Silver (KAG) $ 66.35
  • royal-dollarRoyal Dollar (RUSD) $ 0.999778
  • build-onBUILDon (B) $ 0.248774
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • monadMonad (MON) $ 0.020887

ATM Token Exploited on BNB Chain: $243,500 Drained via Hidden Swap Loophole

0 0


A relatively obscure token called ATM, deployed on the $BNB Smart Chain (BSC), became the latest victim of a smart contract vulnerability. An attacker drained approximately $243,500 by exploiting non-standard logic in the token’s transferFrom() function.

Security monitoring platforms TenArmor flagged the incident on June 4, 2026. The alerts highlighted how custom token mechanics, often added for fees, liquidity provision, or rewards, can create serious exploitable weaknesses when not properly secured.

#CertiKInsight

We have seen an exploit of ~$243K on ATM token. The transferFrom() includes logic to swap 20% transfer amount of ATM for BSC-USD, so the attacker can repeatedly swap out extra after transfer.

Stay vigilant! pic.twitter.com/hwN1B3Xt0m

— CertiK Alert (@CertiKAlert) June 4, 2026

According to CertiK’s analysis, the core issue lay in the token contract’s transferFrom() implementation. Instead of performing a standard token transfer, the function automatically triggered a swap of 20% of the transferred ATM amount into BSC-USD (or equivalent) through a decentralized exchange router.

This hidden behavior allowed the attacker to repeatedly initiate transfers that extracted far more value than normal approvals should permit. The main attack transaction hash is: 0x37b90a…dcfd86

Contract Address: 0x4fd087…d5a205

Blockchain security alerts detected the suspicious activity at an early stage. The attacker’s address, 0x7e7C1f…CdBAFE, has been associated with previous token contract exploits since 2025. The attack did not rely on flash loans or reentrancy but leveraged the unintended economic side effects of the custom transfer logic.

This latest incident adds to a worrying wave of exploits on $BNB Chain. Just days earlier, TesseraDAO was hit in a major attack where the exploiter minted roughly 99 million TSR tokens, dumped them, and drained around $2.5 million in USDT. The TSR token crashed nearly 99% following the incident.

Public information about the ATM project remains very sparse. There is no widely available official website, whitepaper, or detailed roadmap. The project does not appear to be a major DeFi protocol, and details regarding its intended use case, team background, or total value locked (TVL) before the exploit are not well documented.

As of June 5, 2026, the ATM project team has not issued any official public statement regarding the incident, whether the contract was paused, liquidity status, or any recovery efforts.

Such vulnerabilities are not isolated. In late May 2026, attackers exploited legacy liquidity lockers on DxSale and drained approximately $7.3 million from over 1,400 pools by manipulating unlock timestamps and withdrawing LP tokens. This shows how even older “locked” liquidity from previous cycles can remain at risk.

This incident serves as a classic example of the dangers associated with custom tax-on-transfer or auto-swap mechanisms in ERC-20-like contracts. While such features can serve legitimate purposes, they significantly increase complexity and the attack surface.

Blockchain security experts consistently warn that combining transferFrom() with external calls, such as to DEX routers, requires rigorous auditing, formal verification, and extensive edge-case testing.

  • Always verify smart contracts thoroughly before interacting with them.
  • Revoke token approvals regularly, especially for unknown or low-cap tokens.
  • Prefer projects with multiple independent audits and transparent security practices.

Even though this is a mid-sized exploit by 2026 standards, such incidents continue to erode confidence in the broader DeFi ecosystem. Smaller tokens on chains like $BNB Smart Chain remain frequent targets due to rushed deployments and insufficient security measures.

Users are strongly advised to exercise extreme caution when dealing with new or low-visibility tokens.





Source link

Leave A Reply

Your email address will not be published.