Flash-Loan Reward Exploit Mints Millions of SHARK Tokens on BSC
On Tuesday, May 25, 2021, BSC yield project Autoshark was exploited for approximately $745,000 in profit to the attacker — a comparatively small sum, but notable for arriving just eight hours after PancakeBunny suffered a near-identical attack.
Separately, the piece notes that a different individual had earlier donated $100,000 in DAI to the rekt.news treasury; no link between that actor and the Autoshark incident is established.

Mechanics of the exploit
According to an analysis credited to watchpug, the attacker followed a sequence that mirrored the PancakeBunny exploit:
- Deposited a small amount into the SHARK-BNB vault.
- Took out a flash loan of 100,000 BNB from PancakeSwap.
- Converted 50,000 BNB into SHARK tokens, then sent that SHARK together with the remaining 50,000 BNB to the SharkMinter contract — the pivotal step in the exploit.
- Called getReward against the vault deposit made in step one.
- Because the minter contract's balance now held an artificially inflated amount of SHARK and WBNB (deposited by the attacker in step three), it calculated an enormous "profit" and minted 100 million SHARK as a reward, along with a further 15 million allocated to Dev and 20 million to Referrer.
- Sold the minted SHARK for 102,000 WBNB, repaid the flash loan, and kept roughly 2,200 WBNB in profit.
In short, the 50,000 BNB and matching value of SHARK the attacker deposited into the contract during step three tricked its reward calculation into registering an outsized profit, triggering the mint and dump of 100 million SHARK tokens (plus the 15 million and 20 million Dev/Referrer allocations). The full transaction can be viewed on BscScan.

A recurring pattern on BSC
The incident adds to a growing list of BSC projects tripped up by insufficiently reviewed, closely copied code as the ecosystem matures. Several audit firms tied to these projects have drawn criticism for signing off on code with clear flaws — including one firm in particular singled out for scrutiny.
Get new scam files the moment we publish them — usually 2–3 emails a week.