Low Smart contract exploit Source: SlowMist Hacked

BYToken hacked

The public triggerAutoBurn() function in the BYToken contract on BSC was abused using a flashloan. This burned a large amount of BY directly from the BY/WBNB pair and rewrote reserves, allowing the attacker to drain nearly all WBNB liquidity, netting approximately $87,402.

Estimated loss
$87,402
Protocols
BYToken
Chains
BSC
Confidence
High
First seen
4 Jun 2026, 00:00 UTC

Read the original report ↗ (opens in a new tab)