A 67-Cent Deposit and a Decimal Bug Drained MobiusDAO of $2.15 Million
On May 11, MobiusDAO's Mobius Token (MBU) collapsed after an attacker exploited a basic arithmetic flaw rather than any complex vulnerability. By depositing just 0.001 BNB, the attacker minted 9.73 quadrillion MBU tokens and used them to extract roughly $2.15 million in real stablecoin value. The root cause was a decimal-handling error in the contract's price calculation.
Blockaid first flagged the incident in the early hours of May 11. Cyvers confirmed the exploit shortly afterward, by which point the attacker was already selling off the minted tokens, driving MBU's price to zero. The proceeds were then funneled through Tornado Cash in 21 separate transfers of 100 BNB apiece.

Credit: Blockaid, Cyvers, MobiusDAO, AstraSec, Quill Audits, Noveleader, CertiK
01A three-day-old project with no visible safeguards
MobiusDAO launched on May 8 with minimal infrastructure: a token contract, a barebones website, and marketing language describing "Dimensional Integration" for DeFi and real-world assets. Researchers found no audit on record, possibly no open-source code, no documentation, and no publicly identifiable team — only a Telegram channel and a Twitter account that had been promoting predictions of 10x gains.
By May 11, the project's minting function had been exploited. MobiusDAO stayed quiet for more than 10 hours before releasing a statement that attributed the incident to the "BSC Byzantine consensus mechanism" and pledged cooperation with international law enforcement.
02How the exploit worked
According to Quill Audits' technical breakdown, the flaw sat inside the contract's deposit function. When a user deposited WBNB, the contract called getBNBPriceInUSDT to determine how many MBU tokens to mint in return. That function already returned its price value scaled to 18 decimals — but the deposit function then multiplied the result by an additional 10**18, effectively squaring the decimal scaling.
Quill Audits researcher Noveleader summarized the bug directly: "The contract performed an extra multiplier of 10**18 on the amount the attacker deposited, inflating the amount deposited though the deposited amount was only $0.67."
At the time of the exploit, BNB traded around $656, and that figure was correctly formatted to 18 decimals before the deposit function applied its erroneous second multiplication. As Quill Audits put it, "the problem arises as the function returns the value in 18 decimals, the contract multiplies this value again by 10**18, minting an enormous amount of tokens." The result: a deposit of roughly 0.001 WBNB, worth about 67 cents, produced 9,731,099,570,720,980.659843835099042677 MBU tokens.
03Following the on-chain trail
The attacker first funded the operation through Tornado Cash before deploying infrastructure on BSC:
- Tornado Cash funding transaction: 0x491b6888843f260587e86efaa26b837c6a1c26d17442a526088bb2ec46ee828f
- Attacker address: 0xB32A53Af96F7735D47F4b76C525BD5Eb02B42600
- Attacker's deployed contract: 0x631adFF068D484Ce531Fb519Cda4042805521641
- Victim contract: 0x95e92B09b89cF31Fa9F1Eca4109A85F88EB08531
- MBU token contract: 0x0dfb6ac3a8ea88d058be219066931db2bee9a581
- Exploit transaction: 0x2a65254b41b42f39331a0bcc9f893518d6b106e80d9a476b8ca3816325f4a150

After minting the tokens, the attacker sold them through PancakeSwap, collapsing MBU's price to near zero, then laundered the proceeds through 21 separate Tornado Cash transactions of 100 BNB each.
04An unusual response
Days after the attack, MobiusDAO published another statement describing the incident as a "system data anomaly." The project said it would continue paying 0.5% compound interest twice daily on what it called "pre-attack collateral data," and pledged to "intercept abnormal transactions in real time" and undergo "audits by multiple auditing companies" ahead of a relaunch.
Astrasec's analysis noted that the contract itself did not appear to be public, and that basic protections — a mint cap, input validation, and testing — were all absent. Three days elapsed between the token's launch on May 8 and its effective collapse on May 11, the direct result of one unchecked multiplication in the minting logic.
Get new scam files the moment we publish them — usually 2–3 emails a week.