• bitcoinBitcoin (BTC) $ 64,194.00
  • ethereumEthereum (ETH) $ 1,739.09
  • tetherTether (USDT) $ 0.998954
  • bnbBNB (BNB) $ 587.02
  • usd-coinUSDC (USDC) $ 0.999886
  • xrpXRP (XRP) $ 1.15
  • solanaSolana (SOL) $ 73.25
  • tronTRON (TRX) $ 0.326307
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.03
  • hyperliquidHyperliquid (HYPE) $ 70.87
  • dogecoinDogecoin (DOGE) $ 0.083704
  • usdsUSDS (USDS) $ 0.999656
  • rainRain (RAIN) $ 0.014439
  • leo-tokenLEO Token (LEO) $ 9.57
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • zcashZcash (ZEC) $ 472.83
  • stellarStellar (XLM) $ 0.216031
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • whitebitWhiteBIT Coin (WBT) $ 52.78
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • cardanoCardano (ADA) $ 0.163253
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • moneroMonero (XMR) $ 322.84
  • chainlinkChainlink (LINK) $ 7.98
  • canton-networkCanton (CC) $ 0.152528
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • ethena-usdeEthena USDe (USDE) $ 0.998876
  • susdssUSDS (SUSDS) $ 1.08
  • the-open-networkGram (prev. Toncoin) (GRAM) $ 1.63
  • daiDai (DAI) $ 0.999771
  • labLAB (LAB) $ 13.41
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • bitcoin-cashBitcoin Cash (BCH) $ 199.76
  • memecoreMemeCore (M) $ 2.84
  • hedera-hashgraphHedera (HBAR) $ 0.080575
  • wethWETH (WETH) $ 2,268.37
  • litecoinLitecoin (LTC) $ 44.47
  • hashnote-usycCircle USYC (USYC) $ 1.13
  • suiSui (SUI) $ 0.714367
  • usdt0USDT0 (USDT0) $ 0.998824
  • nearNEAR Protocol (NEAR) $ 2.19
  • global-dollarGlobal Dollar (USDG) $ 0.999755
  • shiba-inuShiba Inu (SHIB) $ 0.000005
  • paypal-usdPayPal USD (PYUSD) $ 0.999882
  • crypto-com-chainCronos (CRO) $ 0.058854
  • avalanche-2Avalanche (AVAX) $ 6.24
  • tether-goldTether Gold (XAUT) $ 4,141.57
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • bittensorBittensor (TAO) $ 232.87
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.13
  • worldcoin-wldWorldcoin (WLD) $ 0.609103
  • pax-goldPAX Gold (PAXG) $ 4,148.99
  • uniswapUniswap (UNI) $ 3.02
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.057911
  • mantleMantle (MNT) $ 0.535085
  • aster-2Aster (ASTER) $ 0.646141
  • ondo-financeOndo (ONDO) $ 0.343500
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • polkadotPolkadot (DOT) $ 0.972162
  • ripple-usdRipple USD (RLUSD) $ 1.00
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • okbOKB (OKB) $ 75.27
  • htx-daoHTX DAO (HTX) $ 0.000002
  • falcon-financeFalcon USD (USDF) $ 0.995503
  • pi-networkPi Network (PI) $ 0.134318
  • usddUSDD (USDD) $ 0.999125
  • skySky (SKY) $ 0.058066
  • bfusdBFUSD (BFUSD) $ 0.999007
  • internet-computerInternet Computer (ICP) $ 2.30
  • bitget-tokenBitget Token (BGB) $ 1.77
  • pepePepe (PEPE) $ 0.000003
  • morphoMorpho (MORPHO) $ 1.83
  • ethereum-classicEthereum Classic (ETC) $ 7.47
  • aaveAave (AAVE) $ 76.52
  • quant-networkQuant (QNT) $ 70.29
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • united-stablesUnited Stables (U) $ 0.999900
  • superstate-short-duration-us-government-securities-fund-ustbInvesco Short Duration US Government Securities Fund (USTB) $ 11.12
  • blockchain-capitalBlockchain Capital (BCAP) $ 107.07
  • kucoin-sharesKuCoin (KCS) $ 7.22
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.21
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • cosmosCosmos Hub (ATOM) $ 1.80
  • usdtbUSDtb (USDTB) $ 0.999614
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • render-tokenRender (RENDER) $ 1.72
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.11
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.080118
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • algorandAlgorand (ALGO) $ 0.094021
  • ethenaEthena (ENA) $ 0.089707
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • kaspaKaspa (KAS) $ 0.029799
  • stable-2​​Stable (STABLE) $ 0.034095
  • wbnbWrapped BNB (WBNB) $ 759.61
  • nexoNEXO (NEXO) $ 0.795330
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.04
  • dexeDeXe (DEXE) $ 15.39
  • justJUST (JST) $ 0.083553
  • gatechain-tokenGate (GT) $ 6.69
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.711586
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • jupiter-exchange-solanaJupiter (JUP) $ 0.210071
  • venice-tokenVenice Token (VVV) $ 14.51
  • flare-networksFlare (FLR) $ 0.007428
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • filecoinFilecoin (FIL) $ 0.787376
  • beldexBeldex (BDX) $ 0.080509
  • ghoGHO (GHO) $ 0.998118
  • xdce-crowd-saleXDC Network (XDC) $ 0.029625
  • yldsYLDS (YLDS) $ 0.999802
  • spiko-amundi-overnight-swap-fund-eurSpiko Amundi Overnight Swap Fund (EUR) (EURSAFO) $ 1.15
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • usual-usdUsual USD (USD0) $ 0.999185
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • hash-2Provenance Blockchain (HASH) $ 0.009970
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • arbitrumArbitrum (ARB) $ 0.084722
  • aptosAptos (APT) $ 0.646019
  • midnight-3Midnight (NIGHT) $ 0.032081
  • clbtcclBTC (CLBTC) $ 76,920.00
  • aerodrome-financeAerodrome Finance (AERO) $ 0.553113
  • usxUSX (USX) $ 0.999397
  • adi-tokenADI (ADI) $ 4.05
  • a7a5A7A5 (A7A5) $ 0.012888
  • injective-protocolInjective (INJ) $ 5.05
  • audieraAudiera (BEAT) $ 1.75
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • pump-funPump.fun (PUMP) $ 0.001432
  • true-usdTrueUSD (TUSD) $ 0.998017
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • ousgOndo Short-Term U.S. Government Bond Fund (OUSG) $ 115.61
  • tbtctBTC (TBTC) $ 70,942.00
  • dashDash (DASH) $ 37.01
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.37
  • euro-coinEURC (EURC) $ 1.15
  • vechainVeChain (VET) $ 0.005044
  • official-trumpOfficial Trump (TRUMP) $ 1.81
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.006825
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.188698
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • bonkBonk (BONK) $ 0.000005
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.610162
  • hastra-primePRIME (PRIME) $ 1.04
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • kite-2Kite (KITE) $ 0.167079
  • lighterLighter (LIT) $ 1.56
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • cocaCOCA (COCA) $ 1.30
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000069
  • sei-networkSei (SEI) $ 0.054608
  • humanityHumanity (H) $ 0.199522
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • skyaiSkyAI (SKYAI) $ 0.362707
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • spx6900SPX6900 (SPX) $ 0.382420
  • apxusdapxUSD (APXUSD) $ 0.890208
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998207
  • the9bitThe9bit (9BIT) $ 0.042687
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • celestiaCelestia (TIA) $ 0.373280
  • blockstackStacks (STX) $ 0.183145
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • sun-tokenSun Token (SUN) $ 0.017220
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • jito-governance-tokenJito (JTO) $ 0.676925
  • curve-dao-tokenCurve DAO (CRV) $ 0.214712
  • ether-fiEther.fi (ETHFI) $ 0.347306
  • kinesis-goldKinesis Gold (KAU) $ 134.84
  • bitwayBitway (BTW) $ 0.131888
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • pyth-networkPyth Network (PYTH) $ 0.036534
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • usdgoUSDGO (USDGO) $ 0.999782
  • gnosisGnosis (GNO) $ 108.20
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • apenftAINFT (NFT) $ 0.00000027
  • noonNoon (NOON) $ 0.751949
  • tezosTezos (XTZ) $ 0.237336
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • bittorrentBitTorrent (BTT) $ 0.00000026
  • royal-dollarRoyal Dollar (RUSD) $ 1.00
  • flokiFLOKI (FLOKI) $ 0.000026
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • grassGrass (GRASS) $ 0.407935
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • conflux-tokenConflux (CFX) $ 0.047448
  • zebec-networkZebec Network (ZBCN) $ 0.002500
  • monadMonad (MON) $ 0.020623
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • pendlePendle (PENDLE) $ 1.41
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06

Slowmist: A Single Missing Line of Code Drained $111,000 From the DIP Token

0 0


A Transfer That Ran Twice

Slowmist flagged the incident in a threat intelligence alert, pinning the loss at 111,097.6 $USDC. The firm said the DIP token’s “_transfer()” function was missing a “return” statement in the branch that handles trades routed through the Pancakeswap router (an offering that decentralized exchanges use to swap tokens against liquidity pools). The team further added:

“The attacker exploited this by calling `skim(router)` to trigger double DIP transfers, then `sync()` to set the DIP reserve to an extremely low value, manipulating the AMM price to drain the pool.”

Despite a detailed breakdown, Slowmist did not name the attacker or say whether the stolen funds could be recovered anytime soon.

The mechanics of the entire operation seem to be quite mundane, given decentralized exchanges such as Pancakeswap rely on automated router contracts to move tokens between traders and liquidity pools. A token is free to add custom logic to its own transfer function, but when that logic mishandles router interactions, the door opens to repeated, unintended payouts.

In the DIP case, the missing “return” meant code that should have stopped after one transfer instead fell through and executed a second time. Each trade that touched the router effectively paid out twice, quietly bleeding $USDC from the pool.

The bug needed no flash loan, oracle trick, or stolen key to work (only a gap in the token’s own code). Such router-aware and fee-on-transfer tokens are common on Binance-linked chains, where projects often bolt extra behavior onto standard token templates. Each added branch is another place for a mistake to hide, and automated swaps can trigger that mistake thousands of times before anyone notices.

Part of a Costly 2026 for DeFi

The DIP loss is small next to the year’s headline breaches, but it fits a steady drumbeat of code-level failures. Slowmist’s public hack database alone has logged more than 2,150 incidents and about $37.8 billion in cumulative losses. In recent days, the tracker recorded a $105,000 loss at Thetanuts Finance and a $2.1 million Aztec Connect exploit.

Even more specifically, one can see that smart contract bugs have driven much of the year’s damage, with DeFi protocols having lost more than $1 billion to hacks and exploits (as of last month). Slowmist itself traced the Aztec Connect drain to a deprecated contract and pinned a $174,570 Grok-Bankr theft on an artificial intelligence (AI) agent that was tricked into approving a transfer.

Lastly, Bitcoin.com News reported earlier in the year that Zetachain paused its mainnet after Slowmist identified a missing access control in its GatewayZEVM contract, another case of a single logic gap handing attackers an opening.

With no recovery confirmed and the attacker still unidentified, the DIP episode bolsters a recurring lesson where a single missing line can be enough to empty a pool, and independent audits remain the main line of defense as DeFi losses climb.



Source link

Leave A Reply

Your email address will not be published.