August 29, 2026
On 27 August 2026, a single BNB Smart Chain transaction used two large WBNB funding legs to manipulate the CCC/WBNB pool and extract 165.47192825151242 WBNB in profit. SentinelTX reconstructed the transaction flow and identified an important attribution distinction: the transaction signer paid the gas, but the profit was routed through a second contract to a different externally owned account.
The evidence supports a reserve-manipulation exploit. It does not, by itself, identify the human operator.
The primary evidence is the successful attack transaction 0x89d8050641019a5a75fa3dafb4f64fb153e4dd30c0f1f51d06a6cc206d3ead43, confirmed at block 118,384,061 on 27 August 2026 at 12:31:31 UTC. Public reporting describes a roughly $117,000 loss. Dollar values are therefore contextual; token amounts and transaction relationships below come from the on-chain reconstruction.
The attack signer 0x7977…13c4 invoked a helper deployed the same day. That helper aggregated 833,662.974022 WBNB across two funding legs. It then donated WBNB to the CCC/WBNB pair and triggered a reserve update before repeatedly trading against a system whose executable pricing depended on the manipulated pool state.
Per confirmed cycle, 44,029.20 CCC moved to the burn address and 61,640.88 CCC returned to the pair. The loop was repeated 80 times. The mechanism matters more than the nominal flash-loan size: temporary liquidity only amplified a pricing dependency that trusted manipulable spot reserves inside one transaction.

Repayment and Profit ExtractionThe first lender received exactly 416,831.487011 WBNB. The second contract received 416,996.958940 WBNB, including the surplus. One minute later, transaction 0x15be1604…acd97f moved the 165.471928 WBNB profit from that contract to 0xca8821…b72a9. Transaction 0xdaeada7c…8bf5 then unwrapped it into native BNB.
At the investigation cutoff, the profit recipient held 165.53941989 BNB. SentinelTX found no confirmed direct deposit from this profit path to a centralized exchange, bridge, or mixer. That creates a live monitoring window, not proof that the funds will remain stationary.
Address | Observed role | Assessment |
|---|---|---|
0x7977…13c4 | Attack transaction signer | Paid gas; did not receive the profit |
0x7738…aeaf | Same-day helper contract | Aggregated funding and executed the sequence |
0x1dbe…97c0 | CCC/WBNB pair | Reserve state was distorted before Sync |
0xf523…41c7 | Victim sale/AMM contract | Executable pricing dependency requires code review |
0xbabf…7a9f | Second funding/repayment contract | Forwarded extracted profit |
0xca8821…b72a9 | Profit recipient EOA | Unwrapped WBNB; funds stationary at cutoff |
The chain proves the transaction ordering, token transfers, repayments, profit amount, and immediate post-exploit destination. It also shows that the signer and the profit recipient were different addresses.
A shared gas source and a shared USDT source create a strong operational-cluster inference between relevant addresses, but they do not establish identity. The ultimate source of the second funding leg remains unresolved. The precise contract-level pricing formula and the relationship between two reported CCC contract identifiers also require separate code and deployment review.
0xca8821…b72a9 for first-hop movement, especially wrapping, bridging, or exchange deposits.This was not simply a “large flash loan” event. The decisive control failure was allowing a manipulable pool state to influence executable pricing within the same transaction. The clearest recovery lead is the profit-recipient EOA, where the extracted value was still visible and had not entered a confirmed obfuscation or off-ramp service at the cutoff.
Sources: SentinelTX on-chain investigation; Defimon Alerts; BitBase incident report.

2 reads