BYToken's autoBurn mechanism drained its PancakeSwap liquidity pool, enabling a $84K flash-loan exploit via reserve manipulation.
Security & Exploits ·
BYToken (BY) suffered a $84,000 exploit on its PancakeSwap liquidity pool due to a flaw in its autoBurn mechanism. The token's _autoBurn function periodically burned tokens from the pool and called sync() to update reserves, causing the BY reserve in the BY/WBNB pair to deplete to approximately 1 wei over time while the WBNB reserve remained at roughly 77,000 WBNB. This extreme imbalance created an exploitable state.
An attacker flash-borrowed 422,497 WBNB from Moolah and executed repeated swaps of the minimal BY reserve through the PancakeSwap router. Because the BY reserve was near zero, each swap drained approximately half of the remaining WBNB, accumulating significant value. The attacker then liquidated the accumulated BY back into the pool to complete the attack cycle.
The exploit yielded approximately 146.6 BNB in profit (~$84,000), with 7 BNB directed to the builder. The vulnerability stems from the autoBurn's failure to account for the x*y=k invariant's sensitivity when one reserve approaches zero, leaving the pool susceptible to reserve manipulation and flash-loan attacks.