BNB Chain recorded a single-transaction attack against Fox Market on August 15, 2026, with the transaction included at block 116,169,049 at approximately 23:32 UTC. The public chain record identifies the initiating account, an attacker-controlled contract and interactions with the Fox LP-bond system and a PancakeSwap USDT/FOX pair. A later reproducible transaction test measured 112,976 USDT plus residual tokens leaving the attack contract after the flash-loan sequence. That is the narrowest defensible loss figure; later security reports rounded the incident to roughly $118,700 or $120,000.

The event mattered less for its absolute size than for what it demonstrated. Fox Market’s bond path relied on a live automated-market-maker quote inside the same atomic transaction that could also move the quoted market. Flash liquidity let one actor magnify that ordering weakness without committing hundreds of millions of dollars for more than one block.

What the chain showed on August 15

Transaction `0x8e1775cbfd44db29744cc6687ff1822d2c47321de6e94062f789ad6181ad5514` called an attack contract from externally owned account `0x5670d36f00bc7F6860B6AfdDb288E3668efc0ef9`. The transaction used multiple sources of borrowed USDT, routed funds through Fox Market’s LP-bond contracts and the PancakeSwap pair, and repaid the borrowed liquidity before completion. Because all legs succeeded together, the attacker did not carry the flash-loan principal beyond the transaction.

The chain establishes the transaction, token movements and final state. It does not, by itself, assign motive or prove every causal claim about the contract design. No event-day primary statement from Fox Market was located in the surviving record reviewed for this reconstruction. Accordingly, the exact economic loss and the distinction between pool impairment, unbacked token issuance and realized attacker proceeds require analytical interpretation rather than a simple reading of one transfer.

The vulnerable sequence

Later independent reconstructions agree on the core mechanism. The FoxLpBondsPool stake path fixed an internal stake amount using the spot price in the USDT/FOX pool before a large USDT-to-FOX swap altered that same pool’s reserves. Liquidity was then added at the changed reserve ratio, but the accounting value was not recalculated from the assets actually deposited or from a manipulation-resistant price.

The treasury contract accepted that stale value, minted FOX-linked bond exposure and paid an immediate referral reward to an attacker-controlled address. The attacker sold the reward back into the now-distorted pool and unwound the borrowed positions in the same transaction. In this reading, the flash loan was an amplifier, not the underlying defect. The design failure was allowing an economically important mint calculation and immediately liquid reward to depend on a spot quote the caller could move during the same execution.

Why the incident mattered

The attack was a compact example of composability turning local assumptions into system-wide risk. A PancakeSwap spot price was valid as a snapshot of one pool, but it was not safe as a settlement oracle for a minting path that could itself reshape the snapshot’s reserves. Atomic execution then ensured that every profitable leg completed or the entire sequence reverted.

For protocols on August 15, 2026, the institutional lesson was specific: borrowed liquidity did not need to break a lending venue to create damage elsewhere. It only needed a downstream application to treat a manipulable pool quote as durable economic truth. The incident also showed why reported “loss” figures can diverge. Net attacker proceeds, gross liquidity removed and newly created unsupported liabilities measure different things and should not be combined.

Later context

Security researchers published fuller traces after August 15. DeFiHackLabs encoded a reproducible fork test, while SlowMist described the stale-price and immediate-referral sequence and estimated a roughly $118,700 loss. Those later analyses clarify the mechanism; they were not part of the information set available when the transaction first appeared on-chain.

Primary sourceBNB Chain exploit transaction on BscScan

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.