Movie Token exploited for $242K via deflationary token logic flaw allowing unbounded pending burn accumulation and pair reserve manipulation.
Security & Exploits ·
Movie Token suffered a $242K loss on March 10, 2026, through an exploit targeting a flaw in its deflationary token mechanics. An attacker flash-loaned approximately 358,681 WBNB, purchased roughly 10 billion MT tokens via PancakeSwap, then triggered the protocol's 10% sell tax by returning MT to the trading pair during a flash swap callback. This action recorded approximately 9 billion MT as "pending burn" in the contract's pendingBurnAmount variable.
The attacker then called distributeDailyRewards on the LP mining contract, which executed a burn operation that removed approximately 6.7 billion MT directly from the pair's balance and invoked pair.sync(). This collapsed the pair's reserves from roughly 6.7 billion MT and 1,201 WBNB to just 21 million MT and 1,201 WBNB—the minimum liquidity floor. At this severely manipulated exchange rate, the attacker swapped their remaining 10 billion MT for approximately 1,198 WBNB, repaid the flash loan, and realized a profit of roughly 381.7 WBNB.
The vulnerability stems from two design gaps: MT._transfer() at line 713 accumulates pending burn amounts without any limit, and _executePendingBurn() at line 321 drains the pair's token balance without reentrancy protection against same-transaction manipulation. It remains unclear whether the protocol has issued a fix or whether further safeguards have been deployed.