Exploit via initcode vulnerability on BSC drained $3.66M from EOA with hacker profit of $4.19M, affecting Venus, PancakeSwap, and Thena protocols.
Security & Exploits ·
An exploit via initcode vulnerability on the Binance Smart Chain drained approximately $3.66 million from an externally owned account on March 15, 2026. The attacker realized a profit of $4.19 million, with additional losses recorded across two other accounts totaling around $4.7 million combined.
The incident involved interactions with three major protocols: Venus (TVL: $1.28 billion), PancakeSwap (TVL: $1.89 billion), and Thena (TVL: $53.5 million). The vector exploited an initcode mechanism—code executed during smart contract deployment—though specific technical details of how the vulnerability was weaponized remain unclear from available disclosures.
No statement has yet been issued by the affected protocols regarding root cause analysis, remediation steps, or whether users of these platforms face broader systemic risk. The scope of exposure beyond the identified accounts and the attack's replicability on other chains or protocols remain to be determined.