How an Ignored Audit Warning Let a Fake Liquidity Pool Drain $5M from BetterBank on PulseChain
BetterBank, a lending protocol on PulseChain that had been operating for roughly six weeks, lost $5 million after an attacker found a way to mint unlimited bonus tokens through a self-created liquidity pair. The exploit itself relied on no advanced technique — it was the kind of LP manipulation any competent auditor would recognize. What turned it into a $5 million loss was a decision made months earlier: BetterBank's team had downgraded a warning about this exact attack path to "low priority" after auditor Zokyo flagged it.
01The mechanism

BetterBank's protocol included a bonus-minting feature that rewarded ESTEEM tokens to anyone buying FAVOR, intended to incentivize genuine trading activity. Chaofan Shou later explained how this was abused: an attacker could spin up their own liquidity pool on PulseX pairing the legitimate, protocol-registered FAVOR token against a worthless token of their own creation, then perform repeated swaps through that pool to farm bonus rewards, later converting them to real value.
Ordinarily, aggressive bulk swapping would have triggered BetterBank's steep 50% tax meant to make this kind of dumping unprofitable. But that tax logic only applied to pairs BetterBank had officially designated — a self-made LP fell outside its scope and incurred no tax at all. The system had no way to distinguish organic FAVOR trading from a counterfeit pool built purely to exploit the bonus mechanism, and it kept minting bonus tokens as the attacker continued swapping. The combination — unlimited bonus issuance paired with zero tax friction — was what drained the protocol.
02Timeline of the attack
BetterBank first signaled trouble on a Monday morning, when the draining began. The team paused the protocol within minutes of detecting the exploit and began assessing the damage.
Primary attacker address: 0x48c9f537f3f1a2c95c46891332E05dA0D268869B
The attacker's ETH wallet had originally been funded with roughly $450 routed through Tornado Cash, via transaction 0x64637619d3052ed3350402ca0a821eb907c34836c381a91ee8041a90ddad20c3 — a small seed amount that suggests the exploit was planned in advance rather than discovered opportunistically.
Three contracts, all deployed by the primary attacker address, formed the infrastructure of the attack:
- 0x767C5a70CDa0D9469ccE3a56653E1d170D9849c3
- 0x792CDc4adcF6b33880865a200319ecbc496e98f8
- 0x18Dd9E3F039F319c854c389fC87b5295d3cb7f94
Together these contracts let the attacker build a parallel system that BetterBank's own logic couldn't flag as illegitimate.
After the funds were extracted, everything was converted to ETH and bridged to Ethereum before being routed toward Tornado Cash. CertiK reported the attacker converted about 309 ETH in the process, though Bitcoin World cited a figure closer to 215 ETH for the initial conversion. Notably, the attacker later sent back 550 million pDAI to the protocol — a partial-return gesture that is unusual for this kind of exploit.
03The audit that was overruled
Roughly three months before BetterBank launched, Zokyo's audit identified two related issues: one describing flash-loan exploitation of the Favor Bonus mechanism, and a second describing exactly the attack that ultimately occurred — bogus tokens exploiting Favor Bonus through the UniswapWrapper via a self-deployed contract and LP. In effect, Zokyo had already mapped the path that would later be used to remove $5 million from the protocol.
BetterBank's response was to reclassify the finding as "Low". Their reasoning centered on how Zokyo's proof-of-concept had used legitimate assets like ETH rather than worthless tokens, which produced negative yields in testing rather than a clear profit — leading the team to conclude the underlying risk didn't merit fixing before launch. That interpretation missed the actual point of the finding, which was about bogus tokens being used to break the bonus system, not about the specific token used in the test.
Following the exploit, Zokyo acknowledged that its communication of the risk "could have been clearer", while BetterBank maintained it had never grasped the true danger of the vector Zokyo had documented. Zokyo later stated plainly that its "communication fell short."
04Unanswered questions

Several details around the incident remain unresolved and are worth noting as observations rather than conclusions.
BetterBank had been live for about three weeks before the exploit — enough time to accumulate meaningful TVL, but likely not enough for users to have done deep diligence. The attacker's decision to return 550 million pDAI is atypical: most hostile actors liquidate everything and disappear rather than give back a substantial share of the take. BetterBank's own statement referenced a "successful parley with the exploiter," phrasing that reads more like a negotiated settlement than a straightforward hack response.
Separately, background checks on the team raised questions of their own. LBdefi's Twitter bio lists co-founder roles at both Solidus Money and Grape Finance. Neither project shows much recent activity: Solidus Money has no recent posts, and Grape Finance's last post dates to 2023. Whether this bears any relation to the BetterBank incident is unclear.
BetterBank has continued operating since the exploit and has publicly stated it was hacked rather than having orchestrated a rug pull.
05The bottom line
The technical cause was straightforward: a tax mechanism that only recognized officially sanctioned trading pairs, combined with a bonus system that couldn't tell real liquidity from fabricated liquidity. But the more consequential failure happened earlier, when a documented audit finding describing this precise attack path was downgraded on the basis of a technicality in the proof-of-concept rather than acted on. The partial return of funds and the "parley" language leave open questions about how this incident should ultimately be categorized, but the core facts are not in dispute: an auditor warned, the warning was dismissed, and $5 million left the protocol as a result.
Get new scam files the moment we publish them — usually 2–3 emails a week.