Fact-check findings
What an automated fact-checker found when it re-read DLMC Token (BNB Chain Flash Loan Exploit) against the sources the page cites. Only the most recent review is shown.
These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.
“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.
Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.
unverifiable
3 claimsNo source the reviewer could reach confirms or contradicts the claim.
- #12[unverifiable][awaiting moderator]in section: Flash Loan Exploit — June 24, 2026
“The attacker then redeemed approximately 65,908 DLMC in referral and DAO reward tokens at the inflated price, extracting approximately 1.646 million USDT.”
reviewerThe attacker redeemed approximately 65,908 DLMC in referral and DAO reward tokens at the inflated price, extracting approximately 1.646 million USDT.The $1.646 million USDT extraction figure is well corroborated, but the specific '65,908 DLMC' token count does not appear in any of the three sources consulted; it appears to be a derived/calculated figure not directly sourced. - #19[unverifiable][awaiting moderator]in section: Project Response and Recovery Outlook
“Funds drained in the exploit remained in the attacker-controlled profit receiver address with no known recovery efforts underway.”
reviewerFunds drained in the exploit remained in the attacker-controlled profit receiver address with no known recovery efforts underway.No source consulted confirms the current status of the funds; this is a plausible but unverified claim about the address's present state, since BscScan could not be accessed to check for subsequent outflows. - #20[unverifiable][awaiting moderator]in section: Anonymity and Structural Risk Factors
“The protocol's design incorporates referral reward systems and DAO distributions, structural patterns that security researchers and regulators have associated with high-risk or multi-level marketing-style DeFi schemes.”
reviewerThe protocol's referral reward systems and DAO distributions are structural patterns that security researchers and regulators have associated with high-risk or multi-level marketing-style DeFi schemes.Neither cited source names any specific security researcher or regulator making this association; no named regulatory body or study could be found to substantiate the specific claim as worded. This reads as an uncited generalization rather than a sourced fact.
partially supported
2 claimsThe cited evidence supports part of the claim but not all of it.
- #3[partially supported][awaiting moderator]in the summary
“No team has been publicly identified, no post-exploit response has been issued, and the protocol's referral and DAO reward structure resemble patterns common in high-risk DeFi schemes.”
reviewerNo team has been publicly identified, no post-exploit response has been issued, and the protocol's referral and DAO reward structure resemble patterns common in high-risk DeFi schemes.The 'no team identified' and 'no response issued' clauses are confirmed. The characterization that the referral/DAO structure 'resemble patterns common in high-risk DeFi schemes' is an editorial generalization not directly sourced; see the more specific finding on sections[4]. - #7[partially supported][awaiting moderator]in section: Project Overview
“Contact information is limited to two email addresses and social media accounts on Facebook, X (Twitter), Instagram, YouTube, and Telegram under the handle 'DlmcOfficial.'”
reviewerContact information is limited to two email addresses and social media accounts on Facebook, X (Twitter), Instagram, YouTube, and Telegram under the handle 'DlmcOfficial.'Four of five claimed platforms confirmed; Telegram could not be found on the current live site, and a WebSearch for a DlmcOfficial Telegram channel returned nothing relevant. This may reflect a site change since the page was researched rather than an error, so it is flagged as partially supported rather than disputed.citedwww.dlmc.io/
confirmed
18 claimsThe cited evidence supports the claim as written.
- #1[confirmed][no action needed]in the summary
“DLMC (Decentralized Legacy Management Corporation) is a BNB Chain DeFi token that suffered a flash loan price manipulation exploit on June 24, 2026, resulting in a net loss of approximately $222,560 in USDT from its treasury.”
reviewerDLMC is a BNB Chain DeFi token that suffered a flash loan price manipulation exploit on June 24, 2026, with a net loss of approximately $222,560 in USDT from its treasury.Three independent sources agree on the date, mechanism category, and loss figure. - #2[confirmed][no action needed]in the summary
“The project markets itself as a fully decentralized, CertiK-verified ecosystem with renounced ownership, but a design flaw in its internal price calculation allowed an attacker to drain funds in a single transaction.”
reviewerThe project markets itself as a fully decentralized, CertiK-verified ecosystem with renounced ownership, but a design flaw in its internal price calculation allowed an attacker to drain funds in a single transaction.Independently fetched the live dlmc.io site (WebFetch tool returned 403, but a direct HTTP GET succeeded) and confirmed the exact marketing claims.citedwww.dlmc.io/ - #4[confirmed][no action needed]in section: Project Overview
“The project's website (dlmc.io) claims the protocol is '100% fully decentralized,' CertiK-verified, and features renounced ownership with locked liquidity.”
reviewerThe DLMC website claims the protocol is '100% fully decentralized,' CertiK-verified, and features renounced ownership with locked liquidity.All four marketing claims independently confirmed on the live dlmc.io site as of review date.citedwww.dlmc.io/ - #5[confirmed][no action needed]in section: Project Overview
“The minimum deposit is marketed as $1.”
reviewerThe minimum deposit is marketed as $1.Confirmed verbatim on the live site.citedwww.dlmc.io/ - #6[confirmed][no action needed]in section: Project Overview
“No team members, founders, or corporate registrations are publicly identified on the project's website.”
reviewerNo team members, founders, or corporate registrations are publicly identified on the project's website.Confirmed by direct review of full site text.citedwww.dlmc.io/ - #8[confirmed][no action needed]in section: Flash Loan Exploit — June 24, 2026
“On June 24, 2026, at approximately 11:15 UTC, an attacker exploited a price manipulation vulnerability in the DLMC smart contract on BNB Chain, resulting in a net loss of approximately $222,560 USDT from the protocol's treasury. The attack occurred in block 106091607.”
reviewerExploit occurred June 24, 2026 at approximately 11:15 UTC in block 106091607, resulting in a net loss of approximately $222,560 USDT.Corroborated by three independent sources including a specialized technical postmortem. - #9[confirmed][no action needed]in section: Flash Loan Exploit — June 24, 2026
“The attacker's externally owned account (EOA) is identified as 0x74c4a756933d0f713facb1dea325ef511646c3b1, and profits were routed to a receiver address at 0x701bb7b460ae231dbbcfa3d87f0ab5b458429699. The vulnerable DLMC contract address is 0xf2ca2a3572b26ae7c479dc7ae36d922113b1bdf2.”
reviewerThe attacker's EOA is 0x74c4a756933d0f713facb1dea325ef511646c3b1, the profit receiver address is 0x701bb7b460ae231dbbcfa3d87f0ab5b458429699, and the vulnerable DLMC contract address is 0xf2ca2a3572b26ae7c479dc7ae36d922113b1bdf2.BscScan itself could not be reached directly (403 to automated requests), but all three addresses are corroborated identically across three independent write-ups. - #10[confirmed][no action needed]in section: Flash Loan Exploit — June 24, 2026
“The attacker flash-swapped approximately 1.42 million USDT from a PancakeSwap liquidity pair and used helper contracts to execute large purchases of DLMC tokens totaling approximately $1.42 million USDT. These purchases artificially inflated the protocol's internal USDT reserves.”
reviewerThe attacker flash-swapped approximately 1.42 million USDT from PancakeSwap and used helper contracts to buy approximately $1.42 million in DLMC, inflating internal USDT reserves.Confirmed with precise figures from the DarkNavy technical writeup. - #11[confirmed][no action needed]in section: Flash Loan Exploit — June 24, 2026
“Because the contract's internal pricing function calculated price as USDT reserves divided by circulating supply — and excluded newly minted contract-held tokens from the circulating supply denominator — the internal price of DLMC surged from approximately $0.41 to approximately $25 per token.”
reviewerThe internal price of DLMC surged from approximately $0.41 to approximately $25 per token due to the reserves/circulating-supply pricing flaw.Precisely corroborated by the technical postmortem's exact price figures. - #13[confirmed][no action needed]in section: Flash Loan Exploit — June 24, 2026
“After repaying the flash loan of approximately 1.424 million USDT, the attacker retained a net profit of approximately $222,560 USDT.”
reviewerAfter repaying the flash loan of approximately 1.424 million USDT, the attacker retained a net profit of approximately $222,560 USDT.Matches the technical postmortem's figures closely. - #14[confirmed][no action needed]in section: Flash Loan Exploit — June 24, 2026
“TenArmor Security's monitoring system (TenArmorAlert) first publicly flagged the suspicious activity on June 25, 2026, followed by DeFi_Nerd_sec and DefimonAlerts.”
reviewerTenArmor Security's monitoring system (TenArmorAlert) first publicly flagged the suspicious activity on June 25, 2026, followed by DeFi_Nerd_sec and DefimonAlerts.Ordering and account names both confirmed. - #15[confirmed][no action needed]in section: Root Cause: Self-Referential Pricing Trap
“Security researchers identified the core vulnerability as a 'self-referential pricing trap' within the protocol's _updatePrice() function.”
reviewerThe core vulnerability is a 'self-referential pricing trap' in the protocol's _updatePrice() function.The specific term 'self-referential pricing trap' is attributable to the CryptoTimes source; confirmed as accurately attributed since it is one of the two sources cited for this section. - #16[confirmed][no action needed]in section: Root Cause: Self-Referential Pricing Trap
“The function calculated token price as USDT reserves divided by circulating supply, but the protocol's buy function minted the majority of new DLMC tokens directly to the contract address itself (address(this)) rather than distributing them to external holders.”
reviewerThe protocol's buy function minted the majority of new DLMC tokens directly to the contract address itself (address(this)), excluding them from circulating supply.Consistent mechanism description across all three sources. - #17[confirmed][no action needed]in section: Root Cause: Self-Referential Pricing Trap
“Researchers noted that despite the project having received a CertiK smart contract verification, the audit did not catch this economic logic vulnerability.”
reviewerDespite receiving CertiK smart contract verification, the audit did not catch this economic logic vulnerability.Confirmed by the CryptoTimes source, which is one of the two cited for this section (the Cryip source does not discuss CertiK). - #18[confirmed][no action needed]in section: Project Response and Recovery Outlook
“As of June 25, 2026, no public post-exploit statement, compensation plan, or remediation roadmap has been issued by the DLMC team or any identifiable representative.”
reviewerAs of June 25, 2026, no public post-exploit statement, compensation plan, or remediation roadmap has been issued by the DLMC team.The claim is explicitly date-qualified ('As of June 25, 2026') so it remains accurate regardless of the current review date; a broader search found no evidence any statement has been issued since. - #21[confirmed][no action needed]in section: On-Chain Identifiers
“The following on-chain identifiers are associated with the DLMC exploit. The vulnerable DLMC smart contract is deployed on BNB Chain at address 0xf2ca2a3572b26ae7c479dc7ae36d922113b1bdf2. The attacker's externally owned account is 0x74c4a756933d0f713facb1dea325ef511646c3b1. The profit receiver address, to which the net $222,560 USDT was routed, is 0x701bb7b460ae231dbbcfa3d87f0ab5b458429699. The exploit transaction occurred in BNB Chain block 106091607. PancakeSwap was the source of the flash loan used in the attack.”
reviewerThe vulnerable DLMC contract, attacker EOA, profit receiver address, exploit block, and flash loan source (PancakeSwap) are as identified.This section duplicates identifiers already verified in sections[1]; all values are consistent across the three independent sources consulted. - #22[confirmed][no action needed]in the timeline
“Flash loan exploit executed at approximately 11:15 UTC in BNB Chain block 106091607. Attacker used a 1.42 million USDT PancakeSwap flash loan to inflate the internal DLMC price and drain approximately $222,560 net from the treasury.”
reviewerFlash loan exploit executed June 24, 2026 at approximately 11:15 UTC in block 106091607; attacker used a 1.42 million USDT PancakeSwap flash loan to drain approximately $222,560 net from the treasury.Timeline date (2026-06-24) and event content confirmed consistent with sections[1]. - #23[confirmed][no action needed]in the timeline
“TenArmorAlert, DeFi_Nerd_sec, and DefimonAlerts publicly flagged the exploit. Security reports analyzed the root cause as a self-referential pricing trap in the _updatePrice() function.”
reviewerTenArmorAlert, DeFi_Nerd_sec, and DefimonAlerts publicly flagged the exploit on June 25, 2026; security reports analyzed the root cause as a self-referential pricing trap in the _updatePrice() function.Timeline date (2026-06-25) and event content confirmed.