Two BNB transfers landed on an address that had never held a cent, ten seconds apart. Eighty-one minutes after the second one, LoopsDAO’s liquidity pool on BNB Chain was short $696,000, and by today the same pool that carried roughly $28 million in tracked value earlier this month holds $33.

No named security firm has published on this one. The trail exists because a handful of independent on-chain researchers pieced it together themselves, transaction by transaction, and CryptoNewsLive independently re-checked the core claims directly on BscScan rather than taking any single account’s word for it.

Eighty-One Minutes, Timestamped To The Second

The researcher behind the account BlockWatchdog published the most detailed account found anywhere of what happened on August 2. At 14:39:44 UTC, 99.9483 BNB arrived at a cold wallet that had sat flat at zero since at least July 9. Ten seconds later, a second transfer took it to 199.8965 BNB. Both arrived through internal calls rather than plain transactions, meaning whoever sent them is hidden behind execution traces the researcher couldn’t pull. Between 14:43 and 15:05 UTC, seven sales converted that BNB into stablecoin. A new wallet received a small funding transfer at 15:08, then larger sums followed at 15:42. By 15:59:59 UTC, the attack contract had drawn a flash loan of roughly $43.7 million from about eighteen separate sources in a single call, and one minute later the extracted funds, $700,535.14 in USDC, left the pool.

BlockWatchdog's X thread opening the LOOPSDAO investigation
X (@BlockWatchdog) — the opening of the only detailed forensic account of the incident found anywhere, screenshotted August 5, 2026.
BlockWatchdog's minute-by-minute timeline of the LOOPSDAO exploit
X (@BlockWatchdog) — the second-by-second timeline from BNB funding to flash loan draw, screenshotted August 5, 2026.

A Flash Loan Used To Fake A Deposit, Not Steal One Directly

DeFiLlama classifies the incident as a Price Manipulation Attack under Protocol Logic, and an independent Chinese-language account posting under the handle 月下李白 gate 85 described the actual mechanism a day before most English-language coverage existed: the attacker borrowed the $44 million flash loan, used it to push the pool’s internal collateral price roughly 71 times higher than normal, and that inflated price let the contract register a deposit that was never real. The whole sequence crossed the protocol’s interest-calculation boundary in under a second before unwinding, leaving the attacker with the difference. A separate account, Trueo, listed the same incident in a weekly roundup of three small DeFi exploits that week, describing it independently as “LPDFI lost ~$690K to a flash-loan price-skew on BSC.”

What CryptoNewsLive Checked Directly On BscScan

Rather than rely on any researcher’s summary, CryptoNewsLive pulled the exploit transaction itself. Hash 0x70bbe0aa3c7ef149ecb6128a06025885deaa8fef3f393a505d447d28ab3315d6 confirms as Success in block 113613924, timestamped Aug-02-2026 04:00:00 PM UTC, called from 0x5d289266d85EF671561bA3F253FB79327C193f33 against a verified contract at 0x7f5AD0A998Dcb3f5006F0D152BEBC055979EF711. The BEP-20 transfer log inside that single transaction shows Uniswap V4’s Pool Manager sending $730,528.66 in Binance-Peg USDC into the attack contract, which routes through the PancakeSwap V2 LPD pool and the protocol contract before $693,529.79 in USDC lands back at the attacker’s contract and $7,005.35, exactly the protocol’s own 1% fee, lands at a separate fee address. That last figure matches DeFiLlama’s headline $696,000 almost to the dollar once the fee is added back in.

BscScan transaction details confirming the LOOPSDAO exploit transaction
BscScan — the exploit transaction independently pulled and verified, block 113613924, screenshotted August 5, 2026.
BscScan internal transactions showing the flash loan routed through Uniswap V4 and PancakeSwap
BscScan — the flash loan’s internal transfer path through Uniswap V4’s Pool Manager and the LPD pool, screenshotted August 5, 2026.

A Pool That Went From $28 Million To $33

LoopsDAO’s LPD/USDC pair on PancakeSwap was created 30 days ago, matching BlockWatchdog’s finding that the LPD token itself deployed July 6 and the protocol contract followed on July 14. Pulling the pair’s own market-cap chart on DexScreener shows a steady climb through most of July into the high $20-million range, then a sharp vertical spike past $38 million at the exact moment of the flash loan, the inflated collateral price briefly registering as inflated market cap before the whole thing collapsed straight back down. As of publication the pair carries $33 in liquidity, a $2,400 market cap, and a 24-hour move of negative 95.49 percent. It hasn’t gone completely silent: 1,100 holders remain and 133 trades crossed the pool in the last day, so the token is still technically alive, just gutted.

DexScreener one-month market cap chart for LOOPSDAO showing the spike and collapse
DexScreener (LPD/USDC, PancakeSwap) — the market-cap spike from the manipulated price, then the collapse to $33 in liquidity, screenshotted August 5, 2026.

Who Actually Sent The Money Is Still Unknown

BlockWatchdog was explicit about the limits of the investigation: both BNB transfers arrived through internal calls, which puts the original sender behind execution traces a wallet-history lookup can’t reach, and the researcher declined to guess further. A separate account, 0xSleuthHh, picked up a different thread of the same story, tracing a connected address that sent 15.86 ETH to the exchange ChangeNow, tagging both ChangeNow’s own account and the tracing tool MetaSleuth. Whether that ETH connects to this attacker specifically or a related wallet in the same cluster isn’t confirmed publicly, but it’s the closest anyone has gotten to a cash-out trail.

0xSleuthHh's X post tracing a connected address to a ChangeNow deposit
X (@0xSleuthHh) — a separate researcher’s trace of funds toward the exchange ChangeNow, screenshotted August 5, 2026.

No Word From The Protocol, No Coverage From The Firms That Usually Catch These

A third account, RomanChainOps, checked for an official response and found none: “exploit confirmed onchain; no official LOOPSDAO/LpdFi response found,” citing a $696,952.81 lower-bound loss estimate from Backward Labs and crediting the account exvulsec with the first public alert. Searching X directly for any LoopsDAO or LpdFi project account turns up nothing, only unrelated fan accounts that happen to share the word “loops.” Just as notable is who hasn’t weighed in: as of publication, none of PeckShieldAlert, SlowMist, CertiK Alert, Cyvers, or BlockSec have posted on this incident. For a sub-$1 million exploit on a protocol that had been live for barely three weeks, it appears to have landed below the threshold the larger firms typically cover, leaving the entire public record to independent researchers working the transaction data by hand.

RomanChainOps confirming no official LOOPSDAO response and citing the Backward Labs loss estimate
X (@RomanChainOps) — confirming no official project statement exists and citing the independent loss estimate, screenshotted August 5, 2026.

LoopsDAO has no prior incident on record, which tracks with a protocol that hadn’t yet finished its first month. The DeFiLlama entry lists the loss at $696,000 with no source link and no protocol page behind it, exactly as BlockWatchdog described finding it. Whatever LoopsDAO becomes next, it starts from a pool that’s currently worth less than the gas fee on the transaction that emptied it.