Thursday, June 18, 2026
Catatonic Times
No Result
View All Result
  • Home
  • Crypto Updates
  • Bitcoin
  • Ethereum
  • Altcoin
  • Blockchain
  • NFT
  • Regulations
  • Analysis
  • Web3
  • More
    • Metaverse
    • Crypto Exchanges
    • DeFi
    • Scam Alert
  • Home
  • Crypto Updates
  • Bitcoin
  • Ethereum
  • Altcoin
  • Blockchain
  • NFT
  • Regulations
  • Analysis
  • Web3
  • More
    • Metaverse
    • Crypto Exchanges
    • DeFi
    • Scam Alert
No Result
View All Result
Catatonic Times
No Result
View All Result

A Single Missing Line of Code Drained $111,000 From the DIP Token

by Catatonic Times
June 17, 2026
in Bitcoin
Reading Time: 3 mins read
0 0
A A
0
Home Bitcoin
Share on FacebookShare on Twitter


Key Takeaways

Slowmist stated a lacking return assertion in DIP token’s code drained about $111,098 in USDC.The flaw doubled transfers through Pancakeswap, including to 2,150-plus incidents logged by Slowmist this 12 months.DeFi has misplaced over $1 billion to exploits in 2026, preserving audit demand excessive heading into H2.

A Switch That Ran Twice

Slowmist flagged the incident in a risk intelligence alert, pinning the loss at 111,097.6 USDC. The agency stated the DIP token’s “_transfer()” perform was lacking a “return” assertion within the department that handles trades routed by means of the Pancakeswap router (an providing that decentralized exchanges use to swap tokens towards liquidity swimming pools). The staff additional added:

“The attacker exploited this by calling `skim(router)` to set off double DIP transfers, then `sync()` to set the DIP reserve to an especially low worth, manipulating the AMM worth to empty the pool.”

Regardless of an in depth breakdown, Slowmist didn’t title the attacker or say whether or not the stolen funds may very well be recovered anytime quickly.

The mechanics of all the operation appear to be fairly mundane, given decentralized exchanges resembling Pancakeswap depend on automated router contracts to maneuver tokens between merchants and liquidity swimming pools. A token is free so as to add customized logic to its personal switch perform, however when that logic mishandles router interactions, the door opens to repeated, unintended payouts.

Within the DIP case, the lacking “return” meant code that ought to have stopped after one switch as an alternative fell by means of and executed a second time. Every commerce that touched the router successfully paid out twice, quietly bleeding USDC from the pool.

The bug wanted no flash mortgage, oracle trick, or stolen key to work (solely a niche within the token’s personal code). Such router-aware and fee-on-transfer tokens are widespread on Binance-linked chains, the place tasks usually bolt further habits onto normal token templates. Every added department is one other place for a mistake to cover, and automatic swaps can set off that mistake hundreds of occasions earlier than anybody notices.

A part of a Pricey 2026 for DeFi

The DIP loss is small subsequent to the 12 months’s headline breaches, however it matches a gentle drumbeat of code-level failures. Slowmist’s public hack database alone has logged greater than 2,150 incidents and about $37.8 billion in cumulative losses. In latest days, the tracker recorded a $105,000 loss at Thetanuts Finance and a $2.1 million Aztec Join exploit.

Much more particularly, one can see that sensible contract bugs have pushed a lot of the 12 months’s injury, with DeFi protocols having misplaced greater than $1 billion to hacks and exploits (as of final month). Slowmist itself traced the Aztec Join drain to a deprecated contract and pinned a $174,570 Grok-Bankr theft on a synthetic intelligence (AI) agent that was tricked into approving a switch.

Lastly, Bitcoin.com Information reported earlier within the 12 months that Zetachain paused its mainnet after Slowmist recognized a lacking entry management in its GatewayZEVM contract, one other case of a single logic hole handing attackers a gap.

With no restoration confirmed and the attacker nonetheless unidentified, the DIP episode bolsters a recurring lesson the place a single lacking line will be sufficient to empty a pool, and impartial audits stay the principle line of protection as DeFi losses climb.



Source link

Tags: CODEDipDrainedLineMissingSingletoken
Previous Post

Three Top Takeaways from the HSBC, Google Cloud Partnership

Related Posts

Bitcoin ,000 Rally Call Faces Funding Rate Reality Check
Bitcoin

Bitcoin $70,000 Rally Call Faces Funding Rate Reality Check

June 17, 2026
Oman Launches Mandatory National Bitcoin Mining Pool In State-Backed Push For Regulatory Control
Bitcoin

Oman Launches Mandatory National Bitcoin Mining Pool In State-Backed Push For Regulatory Control

June 17, 2026
Strategy STRC Near Record Low, Bitcoin Buys Unsustainable
Bitcoin

Strategy STRC Near Record Low, Bitcoin Buys Unsustainable

June 17, 2026
Illinois Crypto Tax Draws Industry Fire After Pritzker Signs Budget Package
Bitcoin

Illinois Crypto Tax Draws Industry Fire After Pritzker Signs Budget Package

June 17, 2026
Kalshi’s Perpetual Futures Top .5 Billion in Two Weeks as It Eyes Markets Beyond Crypto
Bitcoin

Kalshi’s Perpetual Futures Top $5.5 Billion in Two Weeks as It Eyes Markets Beyond Crypto

June 17, 2026
First Block, Onpharma Company, and Crito Capital Announce First Solana Sto for U.S. Medical Device Business
Bitcoin

First Block, Onpharma Company, and Crito Capital Announce First Solana Sto for U.S. Medical Device Business

June 17, 2026

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Catatonic Times

Stay ahead in the cryptocurrency world with Catatonic Times. Get real-time updates, expert analyses, and in-depth blockchain news tailored for investors, enthusiasts, and innovators.

Categories

  • Altcoin
  • Analysis
  • Bitcoin
  • Blockchain
  • Crypto Exchanges
  • Crypto Updates
  • DeFi
  • Ethereum
  • Metaverse
  • NFT
  • Regulations
  • Scam Alert
  • Uncategorized
  • Web3

Latest Updates

  • A Single Missing Line of Code Drained $111,000 From the DIP Token
  • Three Top Takeaways from the HSBC, Google Cloud Partnership
  • SpaceX Could Enter Major Index Funds Within Weeks After Trillion-Dollar IPO
  • About Us
  • Advertise with Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact Us

Copyright © 2024 Catatonic Times.
Catatonic Times is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Crypto Updates
  • Bitcoin
  • Ethereum
  • Altcoin
  • Blockchain
  • NFT
  • Regulations
  • Analysis
  • Web3
  • More
    • Metaverse
    • Crypto Exchanges
    • DeFi
    • Scam Alert

Copyright © 2024 Catatonic Times.
Catatonic Times is not responsible for the content of external sites.