A snapshot that never got wiped just cost a BNB Chain token $907,700. MOKE, a reward token whose core contracts went live barely two weeks earlier, watched one attacker claim the exact same liquidity dividend sixty-five separate times before the balance ran dry.

The flaw lived in two functions nobody had thought to pair together. MokeRelease.settle() let any externally owned account write a price straight from the live MOKE/WBNB and WBNB/USDT reserves into contract storage. Separately, MokeLPDividend._syncUserLP() credited a wallet’s stale, already-claimed LP record through the latest dividend accumulator before finally zeroing it out. Same transaction. Same manipulated reserves feeding both checks. Neither function had any reason to doubt a number it had just written itself.

DeFiLlama hacks database listing MOKE at $907,000 on BSC
DeFiLlama — hacks database entry for MOKE, $907,000, Price Manipulation Attack, BSC, dated Aug 2, 2026, screenshotted August 6, 2026.

One Hundred Wallets, One Transaction

Security researcher Defi Nerd, whose account is hosted by the Web3 security shop DarkNavy, published the full attack trace on X within three days of the exploit. It reads less like a hack and more like an assembly line.

The executor pulled 1,334.18 MOKE/WBNB LP tokens out through the MokeLPManager contract, freeing 28.13 WBNB from the pair. It stacked temporary firepower on top, a same-transaction 230,000 BNB flash borrow from Venus, and used that weight to shove the MOKE/WBNB spot price wherever it needed to sit. settle() obediently recorded a rate of 0.000594140821297791 USDT per MOKE, pulled from reserves the attacker itself had just tilted.

Then came the part that turned a clever bug into a six-figure drain. The executor and one hundred EIP-7702 delegated accounts all called claimDividend() against that single manipulated settlement. Sixty-five went through before the pool ran dry; thirty-six reverted. Four identities alone claimed 43,860,308.98 MOKE against a stated pending quota of just 26,059.2 USDT, a mismatch that says plenty about how far the accounting had drifted from reality. MokeLPDividend sold the haul and logged 1,664.62 BNB for distribution across the successful claimants. Once the borrowed BNB was repaid and gas covered, the executor walked away with 1,546.44 BNB net, worth roughly $907,700 at the time.

Defi Nerd technical breakdown of the MOKE exploit on X with attack trace and contract addresses
Defi Nerd (@Defi_Nerd_sec) on X, hosted by DarkNavy — full root-cause and attack-trace thread with executor and contract addresses, screenshotted August 6, 2026.

The transaction itself checks out independently. Block 113652609, timestamped Aug-02-2026 08:50:11 PM UTC, sender and receiver both the executor address 0xE454a9BAC1a44868e4A9Cbe1a4B5ac231D0DCF8a, status success on the outer call despite the 256 internal reverts from the failed delegate claims.

BscScan transaction detail confirming the MOKE exploit transaction hash, block, and executor address
BscScan — exploit transaction 0x0776048b1…, block 113652609, Aug 2, 2026, 08:50:11 PM UTC, screenshotted August 6, 2026.

TenArmor’s own on-chain monitor caught the same transaction independently and posted its alert a day before Defi Nerd’s technical writeup went up, citing an “approximately loss of $907.7K” and linking the identical hash. Two separate trackers, one number, no daylight between them.

None of the Usual Five Showed Up

PeckShieldAlert, SlowMist, CertiK Alert, Cyvers and BlockSec, the five firms whose alerts carry the most weight in this space, have between them posted nothing about MOKE as of this writing. That’s worth saying plainly rather than pretending otherwise. Coverage here came from a smaller on-chain monitor and an independently verifiable BscScan trail, not the household names.

TenArmor security alert on X flagging the MOKE exploit with the same loss figure and transaction link
TenArmorAlert on X — independent detection alert citing the same $907.7K loss and attack transaction, screenshotted August 6, 2026.

The Chart Gave Up Right On Schedule

MOKE isn’t on CoinGecko or CoinMarketCap. A search for the exact ticker on CoinGecko returns one unrelated result, a token called Mokens League. So the only price history that exists lives on-chain, through the PancakeSwap V2 pool itself.

CoinGecko search results for moke showing no listing for the exploited token
CoinGecko — search for “moke” returns zero matches for this token, screenshotted August 6, 2026.

That pool’s own 15-minute chart shows the moment cleanly. The candle carrying the exploit swings from a nominal 54.31 million dollar reading down to 403,280, a 99.26% collapse inside one print, on 980,376 dollars of volume. Read that market-cap figure with a grain of salt, thin liquidity like this inflates fully-diluted numbers into something that was never really tradable at that price, but the shape of the crash is real and it lines up to the minute with the attack transaction. Trading hasn’t come back. Liquidity sits near $161,000 now, the token trades at $0.00192, and the last 24 hours logged exactly zero transactions.

DexScreener market cap chart for MOKE/WBNB showing a vertical crash from 54.31 million to 403.28 thousand
DexScreener — MOKE/WBNB market-cap chart on PancakeSwap, the exploit candle marked at -99.26%, screenshotted August 6, 2026.

The Contract Got Paused. Nothing Else Did.

Three days after the drain, MokeRelease’s own deployer wallet called Pause() on the contract, the most recent transaction it has seen. In the days since, the same deployer has been quietly walking liquidity out of the PancakeSwap pair in batches and burning the MOKE half to the dead address rather than the treasury, a wind-down happening entirely on-chain with zero accompanying words.

BscScan showing the MokeRelease contract's most recent transaction as a Pause call from the contract creator
BscScan — MokeRelease contract, Pause transaction from the deployer address, 3 days after the exploit, screenshotted August 6, 2026.

Because there’s nowhere else to look.

BscScan’s own info page for token carries no listed website and no project social account, its lone Twitter link resolves to BscScan’s own corporate handle rather than anything MOKE-specific. No blog post. No thread from an official account. Just a paused contract and a shrinking pool.

A Second, Unrelated MOKE Complicates Things

Anyone searching the ticker should slow down first. A separate, much older MOKE token sits on the same chain at a different address, 0x273b54cBAE81fC75193C1352f0b3667960f1F1B8, with 451,397 holders and over 12.7 million transfers behind it, nothing to do with the exploited contract at 0x1A35C16cE21903Bc17Fd020c4ED73fEdC70c1b2A and its 1,249 holders. Two tokens, one symbol, one chain. Mixing them up is an easy way to draw the wrong conclusion about either project.

BscScan page for the unrelated, larger MOKE token with 451,397 holders, a different contract from the exploited protocol
BscScan — a separate, pre-existing MOKE token sharing the ticker, unrelated to the exploited contract, screenshotted August 6, 2026.

Whoever built the exploited MOKE has said nothing since the pause.

The pool keeps bleeding, a few thousand dollars at a time, and the only record of what happened sits in block 113652609 and the threads of researchers who were never asked to look.