JUDAO token hack — April 2026
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | April 28, 2026 |
| Target type | Token contract |
| Loss | $227,873Price at time of incident |
| Method | Contract logic errorJUDAO's transfer function moved tokens out of its PancakeSwap pool on every sale and synced the reserves, so an attacker could shrink the pool's JUDAO side and swap for the excess USDT |
| Chains | BNB Chain |
| Outcome | Unresolved |
What happened
JUDAO, a token on BNB Chain, lost 464,205 USDT from its PancakeSwap JUDAO/USDT pool on 28 April 2026, in a transaction at 00:00:00 UTC, of which the attacker took about 227,900 USDT. Defimon Alerts reported the incident later that morning.
According to Defimon, JUDAO's transfer function moved tokens out of the pool on every sale: one rule burned or redistributed an amount equal to the sale from the pool's reserves whenever the price had not risen more than 5% since the previous day, and a "mining" rule sent about 2% of the pool's JUDAO to a dead address and to mining rewards. The attacker bought JUDAO with flash-loaned USDT, sold into the pool to trigger both rules, and swapped the JUDAO credited to the pool for the excess USDT.
This registry read the receipt. The pool's net loss was 464,204.86 USDT: the attacker's address received 205,259.49 USDT and 36 BNB bought with a further 22,613.85 USDT, while 236,331.52 USDT passed through the token contract to five other wallets, apparently the token's fee recipients. The attacker's 227,873 USDT is recorded, with the pool's full loss, Defimon's figure, as the upper end.
Sources
- Defimon Alerts on TelegramSecondary · retrieved 2026-10-06
- DeFiHackLabs exploit reconstructionSecondary · retrieved 2026-10-06
- BNB Chain transaction receipt, read by this registryOn-chain · retrieved 2026-10-06
Changes to this entry
- Recorded on 6 October 2026 in a backfill of 2026 incidents that this registry had missed, found through DeFiHackLabs' reproduction list. The amount was checked against the transaction receipt, read by this registry from a public node.
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "JUDAO token hack — April 2026", iTokenly, accessed 2026-10-06, https://itokenly.com/hacks/judao-token-bsc-april-2026https://itokenly.com/hacks/judao-token-bsc-april-2026Permalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.