BYToken's autoBurn function drained its PancakeSwap pair reserve, allowing an attacker to extract ~$259K via flash-borrowed WBNB and arbitrage exploitation.
Security & Exploits ·
BYToken (BY) suffered an approximate $259,000 loss on June 4, 2026, when an attacker exploited a logic flaw in the token's autoBurn mechanism. The token traded at $0.01375 at the time of the incident. An attacker flash-borrowed 422,497 WBNB and executed a series of arbitrage swaps that extracted roughly 146.6 BNB in profit, with an additional ~7 BNB sent to the builder.
The vulnerability stemmed from BYToken's _autoBurn function, which periodically burned tokens from the PancakeSwap BY/WBNB pair and called sync() to update reserves. This process gradually depleted the BY reserve to approximately 1 wei while the WBNB reserve remained around 77,000 WBNB, creating an extreme price imbalance in the constant-product AMM model. The attacker exploited this by repeatedly swapping tiny amounts of BY for WBNB through the Pancake router; each transaction drained roughly half of the remaining WBNB reserves since the BY side was nearly empty.
The incident highlights risks posed by automated token-burning mechanisms that directly interact with AMM reserves without safeguards. It remains unclear whether the team plans to modify the autoBurn logic, reimburse affected liquidity providers, or implement reserve guards to prevent similar imbalances in future iterations.