PancakeSwap V2 pool exploited for $1.1M via meme token pairing vulnerability on BNB Chain.
Security & Exploits ·
On June 20, 2026, a liquidity pool on PancakeSwap V2 pairing the OLPC and LABUBU tokens was exploited on BNB Chain, draining approximately $1.11 million in USDT value, with the attacker retaining roughly $960,000. The attack involved a transfer of approximately 10 OLPC tokens that triggered the burning of approximately 51.9 million OLPC and 124,000 LABUIB tokens to a dead address, destabilizing the pair's actual balance relative to its cached reserves.
The exploitation pattern follows a deflationary token vulnerability, where a token's burn-on-transfer mechanism desynchronizes a constant-product pair's accounting. After the imbalance, the attacker swept LABUBU tokens from the affected pool and routed them through secondary pairs—LABUBU/WBNB and WBNB/USDT—to exit with 1,115,903 USDT. The attacker address and all involved token and pool contracts have been identified on-chain.
The root cause of the vulnerability remains under investigation, and it is not yet clear whether the issue stems from the token's mechanics, the pool's design, or the interaction between them.