Another PancakeBunny Fork Falls to the Same Reward-Manipulation Trick
After the PancakeBunny exploit set the template, a nearly identical pattern of attacks has continued to surface across Binance Smart Chain.
The latest victim: Merlin Lab, which lost $680,000.

rekt.news generally holds off on covering incidents under $1 million, but this one is worth an exception — mainly because the same underlying technique has now been used three times within a single week. BSC developers, evidently, need to raise their game.
At 03:59:05 AM UTC on May 26, 2021 — less than 48 hours after the Autoshark hack — Merlin Lab, itself another PancakeBunny fork, was hit using a comparable method to both the Bunny and Autoshark incidents. Credit to watchpug for the technical breakdown.
The attacker made off with roughly 240 ETH, worth about $680,000. Transaction details are viewable on BscScan.
The exploit unfolded in six steps:
- A small deposit was made into the LINK-BNB Vault.
- 180 CAKE tokens were sent directly to the LINK-BNB Vault contract — the step that made the exploit possible.
- The attacker called
getRewardagainst the deposit made in step one. - Because the vault contract's balance now showed a large amount of CAKE (thanks to step two), the system read this as a large profit and minted 100 MERL as a reward to the attacker.
- This sequence was repeated 36 times, netting roughly 49,000 MERL tokens in total.
- The MERL was swapped for 240 ETH and moved off BSC via the Anyswap bridge.
The root cause: the protocol treated the vault contract's raw CAKE balance as its performance fee, a value trivially manipulated by simply transferring CAKE tokens directly into the contract.
Publicizing these exploits isn't meant to hand hackers a playbook — though attackers have occasionally thanked us for the coverage regardless. Each incident offers a lesson to the protocols still standing, and when that lesson goes unheeded and user funds are lost anyway, it raises real questions about the diligence of both founders and auditors.

Notably, Merlin Labs had been audited by Hacken on May 15th — just 11 days before this exploit took place.
Both projects — Merlin Labs and its underlying vulnerability class — now sit at the bottom of the rekt leaderboard.
Must try harder.
Get new scam files the moment we publish them — usually 2–3 emails a week.