BYToken hacked
The public triggerAutoBurn() function in the BYToken contract on BSC was abused using a flashloan. This burned a large amount of BY directly from the BY/WBNB pair and rewrote reserves, allowing the attacker to drain nearly all WBNB liquidity, netting approximately $87,402.
- Estimated loss
- $87,402
- Protocols
- BYToken
- Chains
- BSC
- Confidence
- High
- First seen
- 4 Jun 2026, 00:00 UTC