{"investigation":{"slug":"lmlusdt-staking-protocol","entity_name":"LML/USDT staking protocol","trust_score":4,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"The LML/USDT staking protocol was a yield-bearing staking contract deployed on Binance Smart Chain (BSC) that suffered a catastrophic price manipulation exploit on April 1, 2026, resulting in approximately $950,000 in losses. An attacker aggregated flash loans totaling 309,529,000 USDT, artificially inflated the LML token price by purchasing nearly the entire circulating supply and burning it, then claimed outsized staking rewards against the manipulated price. Stolen funds — converted to 450.6 ETH — were subsequently laundered through Tornado Cash, and no public team response or recovery effort has been documented.","sections":[{"content":"The LML/USDT staking protocol is a decentralized finance (DeFi) yield product deployed on the Binance Smart Chain. It operated as a staking contract through which users could deposit assets and earn rewards denominated in LML tokens, with LML itself trading against USDT in a PancakeSwap liquidity pool. Prior to the April 2026 exploit, LML was priced at approximately $50–$55 per token. The protocol's smart contract code was not publicly verified or open-sourced, which limited independent security review and prevented full public code-level analysis before or after the incident. No formal audit by a recognized security firm has been identified in available public records. The team or developers behind the protocol have not been publicly identified, and no official website, whitepaper, or governance documentation has surfaced in post-incident reporting.","heading":"Overview and Background","sources":[{"url":"https://www.cryptotimes.io/2026/04/01/lml-staking-protocol-exploited-for-950k-on-bsc-token-crashes-99-6/","name":"cryptotimes.io","type":"other","credibility":3},{"url":"https://en.cryptonomist.ch/2026/04/01/lml-protocol-bsc-staking/","name":"en.cryptonomist.ch","type":"other","credibility":3},{"url":"https://coinfomania.com/bsc-lml-protocol-hit-by-950k-price-manipulation-attack/","name":"coinfomania.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On April 1, 2026 (UTC+8), blockchain security firm BlockSec detected a price manipulation attack against the LML/USDT staking protocol through its Phalcon real-time monitoring system. The attack was executed entirely within a single on-chain transaction (hash: 0x805d273a63d905d7827d43f6dc051eafdcd0cb69a07c7eb74358c6a5c6255b47) and resulted in an estimated loss of approximately $950,370.69 USDT. The attacker aggregated a flash loan of 309,529,000 USDT sourced from multiple protocols including Moolah, Venus, Aave V3, PancakeSwap, and Uniswap V3. These funds were deployed to purchase nearly the entire circulating supply of LML tokens from the PancakeSwap LML/USDT pool. The purchased tokens were sent to the burn address (address(0)), permanently removing them from circulation and creating a severe distortion in pool reserve ratios — reported at approximately 67,347x. With the LML spot price artificially inflated, the attacker used a set of pre-funded wallet addresses under their control to call the staking protocol's reward payout function 11 separate times. Because the protocol's reward proxy contract (0xae40...02e4) calculated reward values using the manipulated spot price, each claim disbursed rewards far exceeding what the deposited amounts would have legitimately earned. The attacker then reversed their position, repaid the flash loans, and extracted approximately $950,000 in net profit to their wallet (0x3c00...fb51).","heading":"April 2026 Price Manipulation Exploit","sources":[{"url":"https://www.cryptotimes.io/2026/04/01/lml-staking-protocol-exploited-for-950k-on-bsc-token-crashes-99-6/","name":"cryptotimes.io","type":"other","credibility":3},{"url":"https://www.bitget.com/news/detail/12560605325066","name":"bitget.com","type":"other","credibility":3},{"url":"https://www.panewslab.com/en/articles/019d478c-6698-7558-9ba6-fcded9dc4486","name":"panewslab.com","type":"other","credibility":3},{"url":"https://www.binance.com/en/square/post/307740210174225","name":"binance.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Security analysts identified a fundamental pricing design flaw as the root cause of the exploit. The protocol's updatePrice() function consumed manipulated LP reserve ratios directly as its price input, with no time-weighted average price (TWAP) protection, no external oracle integration (such as Chainlink), and no same-block cooldown mechanism. This meant any sufficiently large and brief spot price spike could be immediately reflected in reward calculations. The reward proxy contract calculated claimable amounts based on a snapshot or internal average price, but disbursed rewards at values derived from the live, manipulable pool price — a mismatch that allowed the attacker to realize rewards priced at the artificial spike while the swap mechanism executed at the same inflated price. The underlying contract source code was not publicly available on BSCScan or equivalent block explorers, compounding the difficulty of pre-deployment auditing and post-exploit forensic analysis. The closed-source nature of the contract has been cited by analysts as an additional risk factor for users of the protocol.","heading":"Critical Smart Contract Vulnerability","sources":[{"url":"https://en.cryptonomist.ch/2026/04/01/lml-protocol-bsc-staking/","name":"en.cryptonomist.ch","type":"other","credibility":3},{"url":"https://www.mexc.com/news/997020","name":"mexc.com","type":"other","credibility":3},{"url":"https://cryptonews.net/news/security/32637254/","name":"cryptonews.net","type":"other","credibility":3},{"url":"https://www.cryptotimes.io/2026/04/01/lml-staking-protocol-exploited-for-950k-on-bsc-token-crashes-99-6/","name":"cryptotimes.io","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, the attacker converted the stolen USDT proceeds into 450.6 ETH and subsequently routed those funds through Tornado Cash, an Ethereum-based privacy mixing protocol. Deposits into Tornado Cash were executed in batched amounts ranging from 0.1 ETH to 100 ETH per transaction, a fragmentation pattern consistent with obfuscation of on-chain transaction trails observed in other high-profile DeFi exploits. The use of Tornado Cash significantly reduces the likelihood of fund recovery, as mixed outputs are difficult to trace to a single originating wallet. No law enforcement action, asset freeze, or wallet identification has been publicly reported in connection with the attacker address (0x3c00...fb51) as of the time of writing.","heading":"Fund Laundering via Tornado Cash","sources":[{"url":"https://www.cryptotimes.io/2026/04/01/lml-staking-protocol-exploited-for-950k-on-bsc-token-crashes-99-6/","name":"cryptotimes.io","type":"other","credibility":3},{"url":"https://phemex.com/news/article/bscs-lmlusdt-staking-protocol-hit-by-price-manipulation-attack-70158","name":"phemex.com","type":"other","credibility":3},{"url":"https://www.kucoin.com/news/flash/bsc-chain-lml-usdt-staking-protocol-suffers-price-manipulation-attack-losses-reach-950-000","name":"kucoin.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The LML token suffered a near-total market collapse as a direct result of the exploit. PancakeSwap trading data shows the token declined from approximately $50–$55 per token to $0.1758 USDT, a drop of approximately 99.66%. This collapse was driven by the attacker's burn of the majority of the token supply into address(0), the subsequent reward-claim dumping of newly minted reward tokens, and immediate loss of market confidence. The protocol's liquidity pool was effectively drained of meaningful value. As of available reporting, the LML token has not recovered any significant portion of its pre-exploit price, and normal trading activity in the LML/USDT pair ceased following the incident. Users who held LML tokens or had staked assets within the protocol sustained near-total losses.","heading":"Market Impact and Token Collapse","sources":[{"url":"https://www.cryptotimes.io/2026/04/01/lml-staking-protocol-exploited-for-950k-on-bsc-token-crashes-99-6/","name":"cryptotimes.io","type":"other","credibility":3},{"url":"https://coinfomania.com/bsc-lml-protocol-hit-by-950k-price-manipulation-attack/","name":"coinfomania.com","type":"other","credibility":3},{"url":"https://www.mexc.com/news/996835","name":"mexc.com","type":"other","credibility":3},{"url":"https://cryptonews.net/news/security/32636825/","name":"cryptonews.net","type":"other","credibility":3}],"severity":"medium"},{"content":"Multiple risk factors beyond the technical vulnerability have been identified by analysts. The protocol's development team was not publicly identified, and no official communications — including incident disclosures, post-mortems, or compensation plans for affected users — have been located in public records following the exploit. The smart contract was not open-sourced on any public blockchain explorer, preventing independent security review prior to user participation. No third-party audit report has been cited by any reporting source. The combination of anonymous development, closed-source contracts, absence of oracle safeguards, and complete silence following a nine-hundred-thousand-dollar exploit raises substantive concerns about whether the protocol was designed with user safety as a priority. Several analysts have noted the attack methodology is consistent with a pattern of BSC-based protocols that suffer predictable price-manipulation exploits due to inadequate security engineering, though no public allegation of intentional insider misconduct has been made with verifiable evidence.","heading":"Transparency and Accountability Concerns","sources":[{"url":"https://en.cryptonomist.ch/2026/04/01/lml-protocol-bsc-staking/","name":"en.cryptonomist.ch","type":"other","credibility":3},{"url":"https://www.panewslab.com/en/articles/019d478c-6698-7558-9ba6-fcded9dc4486","name":"panewslab.com","type":"other","credibility":3},{"url":"https://coinfomania.com/bsc-lml-protocol-hit-by-950k-price-manipulation-attack/","name":"coinfomania.com","type":"other","credibility":3},{"url":"https://cryptonews.net/news/security/32637254/","name":"cryptonews.net","type":"other","credibility":3}],"severity":"medium"},{"content":"Blockchain security firm BlockSec was the primary organization to publicly detect and report the attack, via its Phalcon on-chain monitoring system. BlockSec disclosed that its systems raised an alert and confirmed the roughly $950,000 loss estimate after transaction analysis. PeckShield also flagged the incident. Following the exploit, industry commentators and security researchers cited the incident as a case study in the risks of protocols that use spot-price inputs for reward calculations, emphasizing the necessity of TWAP oracles, external price feeds such as Chainlink, and same-block cooldown mechanisms to prevent flash-loan-assisted manipulation. The incident was widely covered across crypto news outlets including CryptoTimes, Cryptonomist, Coinfomania, PANews, and others. AVOID.NET has flagged this entity based on ZachXBT's identification of the protocol as presenting elevated risk to users.","heading":"Security Community Response","sources":[{"url":"https://www.bitget.com/news/detail/12560605325066","name":"bitget.com","type":"other","credibility":3},{"url":"https://www.panewslab.com/en/articles/019d478c-6698-7558-9ba6-fcded9dc4486","name":"panewslab.com","type":"other","credibility":3},{"url":"https://www.binance.com/en/square/post/307740210174225","name":"binance.com","type":"other","credibility":3},{"url":"https://www.mexc.com/news/997020","name":"mexc.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2026-04","event":"BlockSec Phalcon monitoring system detects suspicious activity targeting the LML/USDT staking protocol on BSC.","source":"","date_original":"2026-04-01"},{"date":"2026-04","event":"Attacker executes price manipulation attack in a single transaction using 309,529,000 USDT in aggregated flash loans; LML token supply largely burned to address(0); reward payout function called 11 times at manipulated price.","source":"","date_original":"2026-04-01"},{"date":"2026-04","event":"LML token crashes 99.66% on PancakeSwap, from approximately $50 to $0.1758 USDT.","source":"","date_original":"2026-04-01"},{"date":"2026-04","event":"Attacker converts approximately $950,370 in stolen USDT to 450.6 ETH and begins routing funds through Tornado Cash in batches of 0.1 to 100 ETH.","source":"","date_original":"2026-04-01"},{"date":"2026-04","event":"Security firms BlockSec and PeckShield publish public disclosures of the exploit; estimated loss confirmed at approximately $950,000.","source":"","date_original":"2026-04-01"}],"sources_used":[{"url":"https://www.cryptotimes.io/2026/04/01/lml-staking-protocol-exploited-for-950k-on-bsc-token-crashes-99-6/","name":"cryptotimes.io","type":"other","archive_url":"http://web.archive.org/web/20260725055435/https://www.cryptotimes.io/2026/04/01/lml-staking-protocol-exploited-for-950k-on-bsc-token-crashes-99-6/","credibility":3,"archive_timestamp":"2026-07-25T05:54:35+00:00"},{"url":"https://en.cryptonomist.ch/2026/04/01/lml-protocol-bsc-staking/","name":"en.cryptonomist.ch","type":"other","archive_url":"http://web.archive.org/web/20260730124729/https://en.cryptonomist.ch/2026/04/01/lml-protocol-bsc-staking/","credibility":3,"archive_timestamp":"2026-07-30T12:47:29+00:00"},{"url":"https://coinfomania.com/bsc-lml-protocol-hit-by-950k-price-manipulation-attack/","name":"coinfomania.com","type":"other","archive_url":"https://web.archive.org/web/20260829175356/https://coinfomania.com/bsc-lml-protocol-hit-by-950k-price-manipulation-attack/","credibility":3,"archive_timestamp":"2026-08-29T17:53:56+00:00"},{"url":"https://www.bitget.com/news/detail/12560605325066","name":"bitget.com","type":"other","archive_url":"https://web.archive.org/web/20260829083657/https://www.bitget.com/news/detail/12560605325066","credibility":3,"archive_timestamp":"2026-08-29T08:36:57+00:00"},{"url":"https://www.panewslab.com/en/articles/019d478c-6698-7558-9ba6-fcded9dc4486","name":"panewslab.com","type":"other","archive_url":"https://web.archive.org/web/20260829122732/https://panews.io/articles/019d478c-6698-7558-9ba6-fcded9dc4486","credibility":3,"archive_timestamp":"2026-08-29T12:27:32+00:00"},{"url":"https://www.binance.com/en/square/post/307740210174225","name":"binance.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:not-found","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.mexc.com/news/997020","name":"mexc.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:gone","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cryptonews.net/news/security/32637254/","name":"cryptonews.net","type":"other","archive_url":"http://web.archive.org/web/20260829113955/https://cryptonews.net/news/security/32637254/","credibility":3,"archive_timestamp":"2026-08-29T11:39:55+00:00"},{"url":"https://phemex.com/news/article/bscs-lmlusdt-staking-protocol-hit-by-price-manipulation-attack-70158","name":"phemex.com","type":"other","archive_url":"https://web.archive.org/web/20260829040019/https://phemex.com/news/article/bscs-lmlusdt-staking-protocol-hit-by-price-manipulation-attack-70158","credibility":3,"archive_timestamp":"2026-08-29T04:00:19+00:00"},{"url":"https://www.kucoin.com/news/flash/bsc-chain-lml-usdt-staking-protocol-suffers-price-manipulation-attack-losses-reach-950-000","name":"kucoin.com","type":"other","archive_url":"https://web.archive.org/web/20260829090316/https://www.kucoin.com/news/flash/bsc-chain-lml-usdt-staking-protocol-suffers-price-manipulation-attack-losses-reach-950-000","credibility":3,"archive_timestamp":"2026-08-29T09:03:16+00:00"},{"url":"https://www.mexc.com/news/996835","name":"mexc.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:gone","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cryptonews.net/news/security/32636825/","name":"cryptonews.net","type":"other","archive_url":"https://web.archive.org/web/20260829113934/https://cryptonews.net/news/security/32636825/","credibility":3,"archive_timestamp":"2026-08-29T11:39:34+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:12.566989+00:00","updated_at":"2026-09-01T03:39:49.016503+00:00"}}