CryptoReal
CASE FILE — May 25, 2021

Flash-Loan Reward Exploit Mints Millions of SHARK Tokens on BSC

On Tuesday, May 25, 2021, BSC yield project Autoshark was exploited for approximately $745,000 in profit to the attacker — a comparatively small sum, but notable for arriving just eight hours after PancakeBunny suffered a near-identical attack.

Separately, the piece notes that a different individual had earlier donated $100,000 in DAI to the rekt.news treasury; no link between that actor and the Autoshark incident is established.

Mechanics of the exploit

According to an analysis credited to watchpug, the attacker followed a sequence that mirrored the PancakeBunny exploit:

Sums referenced in this case file
  1. Deposited a small amount into the SHARK-BNB vault.
  2. Took out a flash loan of 100,000 BNB from PancakeSwap.
  3. Converted 50,000 BNB into SHARK tokens, then sent that SHARK together with the remaining 50,000 BNB to the SharkMinter contract — the pivotal step in the exploit.
  4. Called getReward against the vault deposit made in step one.
  5. Because the minter contract's balance now held an artificially inflated amount of SHARK and WBNB (deposited by the attacker in step three), it calculated an enormous "profit" and minted 100 million SHARK as a reward, along with a further 15 million allocated to Dev and 20 million to Referrer.
  6. Sold the minted SHARK for 102,000 WBNB, repaid the flash loan, and kept roughly 2,200 WBNB in profit.

In short, the 50,000 BNB and matching value of SHARK the attacker deposited into the contract during step three tricked its reward calculation into registering an outsized profit, triggering the mint and dump of 100 million SHARK tokens (plus the 15 million and 20 million Dev/Referrer allocations). The full transaction can be viewed on BscScan.

A recurring pattern on BSC

The incident adds to a growing list of BSC projects tripped up by insufficiently reviewed, closely copied code as the ecosystem matures. Several audit firms tied to these projects have drawn criticism for signing off on code with clear flaws — including one firm in particular singled out for scrutiny.

Autoshark
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.