DLMC token exploited via flash-loan-enabled price manipulation, draining ~$226K through artificial bonding curve inflation and referral bonus minting.
Security & Exploits ·
DLMC, a token on BNB Chain, lost approximately $226,000 in a price manipulation exploit on June 24, 2026. An attacker used a flash loan of 1.42 million USDT from a PancakeSwap pair and two registered affiliate accounts to execute the attack, inflating the token's bonding curve price from $0.1 to roughly $25 and triggering the minting of approximately 73,000 free LPT tokens through the protocol's referral bonus system.
The exploit leveraged DLMC's internal pricing mechanism, which calculates the live price by dividing the USDT reserve by circulating supply. Large buy calls via the affiliate contracts bloated the reserve, artificially pumping the price, while the referral logic automatically minted bonus tokens to the upline addresses. The attacker then sold these near-free bonus tokens at the inflated price, draining the contract's reserve from roughly 1.65 million USDT to near-zero before repaying the flash loan.
The attacker netted approximately 222,500 USDT after loan repayment. The mechanism exploited—specifically the reliance on contract-held reserves for price calculation and the uncapped referral bonus minting tied to buy volume—left no guardrails against this vector. It remains unclear whether the protocol has issued a formal postmortem or deployed mitigations.