SOF token hack — February 2026
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | February 26, 2026 |
| Target type | Token contract |
| Loss | $248,626Price at time of incident |
| Method | Contract logic errorSOF's sell path burned the sold tokens out of its PancakeSwap pool and synced the reserves before the pool worked out the USDT owed, so a seller could empty the pool's SOF side and be paid at the inflated price |
| Chains | BNB Chain |
| Outcome | Unresolved |
What happened
SOF, a token on BNB Chain sold with a mining scheme, lost 248,626 USDT from its PancakeSwap SOF/USDT pool on 14 February 2026, in a transaction at 08:45:28 UTC. CertiK published an analysis on 26 February that covered it together with an attack on the LAXO token eight days later, which used the same class of flaw.
According to CertiK, SOF's transfer logic burned the tokens being sold and synced the pool before the pool calculated how much USDT to pay. The attacker took flash loans worth more than $590m across several protocols and bought 991,223 SOF, leaving only 787 in the pool, then sold 875 SOF it had earned earlier as mining rewards. After the sell fee, exactly the 787 SOF left in the pool were burned, and the 875 SOF were exchanged for the pool's whole USDT balance.
This registry read the transaction's receipt: the pool lost 248,626.25 USDT and the attacker's address kept 225,936.44 USDT after repaying the loans. The pool's loss is recorded, with the attacker's net as the lower end. CertiK reported that about $213,600 of the proceeds was deposited at FixedFloat within half an hour and 20 BNB was sent to Tornado Cash.
Sources
- CertiKSecondary · retrieved 2026-10-06
- CertiK Alert on XSecondary · retrieved 2026-10-06
- BNB Chain transaction receipt, read by this registryOn-chain · retrieved 2026-10-06
Changes to this entry
- Recorded on 6 October 2026 in a backfill of 2026 incidents that this registry had missed; SOF surfaced in CertiK's analysis of the LAXO exploit. The amount was checked against the transaction receipt, read by this registry from a public node.
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "SOF token hack — February 2026", iTokenly, accessed 2026-10-06, https://itokenly.com/hacks/sof-token-bsc-february-2026https://itokenly.com/hacks/sof-token-bsc-february-2026Permalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.