Low Smart contract exploit Source: SlowMist Team

SlowMist reported a security incident at BitBayo, resulting in a loss of approximately $14,000

SlowMist reported a security incident at BitBayo, resulting in a loss of approximately $14,000. The vulnerability was in the Vault's `_withdraw()` function, which transferred the entire token balance when liquidity was zero, allowing an attacker to exploit it.

Estimated loss
$14,000
Protocols
BitBayo
Confidence
High
First seen
9 Oct 2026, 03:38 UTC

Read the original report ↗ (opens in a new tab)