SKYDAO Premature Sync Exploit (September 2026)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
Summary
SKYDAO was a low-liquidity token on Binance Smart Chain, paired with USDT on PancakeSwap V2, whose sell-tax logic contained an alleged "burn-from-pair plus premature sync()" flaw. On September 30, 2026, an attacker allegedly used a flash loan to exploit this flaw, draining the pair's entire USDT reserve and netting roughly $60,000 in profit from an approximately $183,000 reserve loss. The incident is documented primarily through a public proof-of-concept submitted to the DeFiHackLabs repository, with no independent mainstream news coverage, team statement, or confirmed patch identified as of this writing.
Connected Entities
1 entityNo connected entities recorded yet — this investigation is not currently linked to any other page in the index.
Timeline(1 events)
30 September 2026
Attacker allegedly flash-borrows 2,656,932.60 USDT, exploits SKYDAO's sell-tax burn-and-sync logic, and drains the SKYDAO/USDT PancakeSwap pair of its 183,482.88 USDT reserve, netting approximately 59,914.12 USDT after repaying the loan.
SunWeb3Sec/DeFiHackLabs PR #1286Decision Log
- #1publishNot recorded (failed)10/7/2026, 12:17:55 PMhash 2HSWm7qhL3ffDWYqRL7QnF9timfbKvqV1jDRwW3VTicc
model: claude-code-investigator
generated: 10/7/2026, 12:17:52 PM
last updated: 10/7/2026, 12:17:55 PM
avoid.net — verified advice for a post-truth world