T
iTokenly

BCE token hack — March 2026

Verified — 3 sourcesLast checked October 6, 2026

Incident facts

Date of incident
Publicly disclosedMarch 23, 2026
Target typeToken contract
Loss$800,009Price at time of incident
MethodContract logic errorBCE burned an accumulated 'scheduled destruction' amount directly out of its PancakeSwap pool on the next ordinary transfer and synced the reserves, so an attacker could empty the pool's BCE side and sell into the distorted price
ChainsBNB Chain
OutcomeUnresolved

What happened

BCE, a deflationary token on BNB Chain, lost 800,009 USDT from its PancakeSwap BCE/USDT pool on 23 March 2026, in a transaction at 05:59:13 UTC. Defimon Alerts reported it the same day, estimating the pool's liquidity before the attack at $1.6m.

According to Defimon and a DeFiHackLabs reconstruction, BCE recorded a "scheduled destruction" amount whenever tokens were sold into the pool, and on the next ordinary transfer it burned that amount directly from the pool and synced the pool's reserves. The attacker funded itself with flash loans from the Moolah lending protocol and borrowings from Venus, built up a large scheduled destruction through two flash swaps, triggered the burn so that the pool was left with almost no BCE, and sold its remaining BCE for the pool's USDT.

This registry read the receipt. The pool lost 800,009.32 USDT; the attacker's address kept 680,007.93 USDT, and 120,001.40 USDT was converted into 189.8 BNB and paid out of the attack contract, a payment of about 15% of the gross profit that DeFiHackLabs also reproduces. The pool's loss is recorded, with the attacker's net as the lower end. No statement from the project has been found.

Sources

  1. Defimon Alerts on TelegramSecondary · retrieved 2026-10-06
  2. DeFiHackLabs exploit reconstructionSecondary · retrieved 2026-10-06
  3. BNB Chain transaction receipt, read by this registryOn-chain · retrieved 2026-10-06

Changes to this entry

  • Recorded on 6 October 2026 in a backfill of 2026 incidents that this registry had missed, found through DeFiHackLabs' reproduction list. The amount was checked against the transaction receipt, read by this registry from a public node.

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "BCE token hack — March 2026", iTokenly, accessed 2026-10-06, https://itokenly.com/hacks/bce-token-bsc-march-2026
https://itokenly.com/hacks/bce-token-bsc-march-2026

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.