T
iTokenly

MOKE hack — August 2026

Verified — 3 sourcesLast checked October 6, 2026

Incident facts

Date of incident
Publicly disclosedAugust 3, 2026
Target typeToken contract
Loss$907,700Price at time of incident
MethodOracle or price manipulationMokeRelease's settle() fixed the claim price from manipulable PancakeSwap spot reserves and accepted calls from any externally owned account, so an attacker holding a 45,000 USDT release quota crashed the price, settled it and claimed about 41.68m MOKE
ChainsBNB Chain
OutcomeUnresolved

What happened

MOKE, a token project on BNB Chain, lost about $907,700 on 2 August 2026, when an attacker used its token-release contract to mint about 41.68m MOKE and turned them into BNB. The attack was a single transaction at 20:50:11 UTC in block 113,652,609. The security firm TenArmor flagged it as a suspected exploit and The Crypto Times reported it on 3 August. The MOKE team has not published a post-mortem.

According to a reconstruction published on 5 October by DeFiHackLabs, an exploit-reproduction project, which checked it against the contracts' verified source code, the flaw was in MokeRelease, the contract that releases MOKE to participants against USDT quotas. Its settle() function fixes the MOKE price used for claims from the live spot reserves of PancakeSwap pools, and one of its permission checks lets any externally owned account call it. The attacker held a legitimate participant quota of 45,000 USDT. Using borrowed liquidity, it crashed the spot price, called settle() to fix the crashed price and then called claim(), which minted 41,684,057 MOKE against the same quota, about 200 times the honest amount. Because that permission check rejects calls made through a contract, the attacker ran its code from its own address through an EIP-7702 delegation. Released MOKE can only move through whitelisted handlers, so the attacker cashed it out for BNB through the project's own LP dividend vault and about 100 accounts it had prepared in advance.

This registry read the transaction's receipt. Its WBNB deposit, withdrawal and transfer events are consistent with the attacker's address ending about 1,546.5 BNB up, in line with DeFiHackLabs' figure of 1,546.54 BNB. At the BNB price of that hour, about $589, that is roughly $910,000, consistent with TenArmor's $907,700, which is the figure recorded. Earlier versions of this entry dated the attack 3 August and gave no mechanism. No recovery, bounty offer or statement from the MOKE team has been reported.

Sources

  1. The Crypto TimesSecondary · retrieved 2026-10-06
  2. DeFiHackLabs exploit reconstructionSecondary · retrieved 2026-10-06
  3. BNB Chain transaction receipt, read by this registryOn-chain · retrieved 2026-10-06

Changes to this entry

  • Changed from reported to verified. DeFiHackLabs published a reconstruction of the exploit on 5 October, and this registry read the transaction itself: it ran at 20:50 UTC on 2 August, not on 3 August, and left the attacker about 1,546.5 BNB up, consistent with the $907,700 already recorded. Vector changed from undisclosed to oracle manipulation.

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "MOKE hack — August 2026", iTokenly, accessed 2026-10-06, https://itokenly.com/hacks/moke-token
https://itokenly.com/hacks/moke-token

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.