← SKYDAO (BSC Swap Logic / Premature Sync Exploit, September 2026)1 decision on this page
Audit log
Every state-changing event for SKYDAO (BSC Swap Logic / Premature Sync Exploit, September 2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-10-07 13:22:24ZScore: ? → ? (no score change)anchorfailed
- chain
- ●—
- hash
3yNgGRLU5xVZ…ijpXMkEFsha256 → base58
verifying row…canonical bytes (10820 B) ▸
{"actor":"system:backfill","investigation_id":"dc52ecd8-d86c-4952-b9a7-8ac81d743a5d","kind":"publish","page_slug":"skydao-bsc-swap-logic-premature-sync-exploit-september-2026","published_at":"2026-10-07T13:22:23.966Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"SKYDAO (BSC Swap Logic / Premature Sync Exploit, September 2026)","sections":[{"content":"On September 30, 2026, the SKYDAO/USDT liquidity pair on PancakeSwap V2 (BNB Chain) was drained of its entire USDT reserve of approximately 183,482.88 USDT. The attacker netted roughly 59,914.12 USDT after repaying a flash loan. The exploit is classified as a protocol logic flaw — specifically a burn-from-pair combined with a premature sync() call — not a market manipulation or oracle attack. The loss figure of approximately $183,483 is sourced from on-chain data reproduced in DeFiHackLabs PR #1286 and corroborated by the Nominis September 2026 monthly report.","heading":"Exploit Overview","severity":"high","sources":[{"credibility":2,"name":"DeFiHackLabs PR #1286 — Add SKYDAO exploit PoC (burn-from-pair + premature sync)","type":"research","url":"https://github.com/SunWeb3Sec/DeFiHackLabs/pull/1286"},{"credibility":2,"name":"Nominis Monthly Report — Crypto Exploits and Attacks in September 2026","type":"news_article","url":"https://www.nominis.io/insights/nominis-monthly-report-crypto-exploits-and-attacks-in-september-2026"}]},{"content":"SKYDAO's sell-transfer logic applies a 35% tax on sell transactions. When a sell is initiated against the SKYDAO/USDT pair, the gross token amount is handed to a pool controller before the pair is credited with the seller's net 65% share. The pool controller then: (1) sells the tax portion, (2) burns the pair's entire SKY token balance to the dead address, and (3) calls sync() on the pair. This sync() call locks in a near-zero recorded SKY reserve in the pair's state, because the net tokens from the original sell have not yet settled into the pair's balance. Once the real balance lands, the pair's actual SKY balance exceeds what sync() recorded as the reserve. A direct pair.swap() call can then extract the pair's USDT against that stale, artificially near-zero SKY reserve. The vulnerability is permissionless — there is no owner or admin gate between the attacker and this code path, as confirmed by the DeFiHackLabs PoC author's review of SKYDAO's verified source code.","heading":"Technical Root Cause: Premature sync() in Sell-Tax Path","severity":"critical","sources":[{"credibility":2,"name":"DeFiHackLabs PR #1286 — SKYDAO exploit PoC source file (SKYDAO_exp.sol)","type":"research","url":"https://github.com/SunWeb3Sec/DeFiHackLabs/pull/1286"},{"credibility":2,"name":"DeFiHackLabs — SKYDAO_exp.sol on-chain identifiers (BNB Chain block 124,921,242)","type":"on_chain","url":"https://github.com/SunWeb3Sec/DeFiHackLabs/blob/main/src/test/2026-09/SKYDAO_exp.sol"}]},{"content":"The attacker (EOA 0x5C9214d91eA1d2D6A46F80457c25a6e7e4D56EBc) executed the exploit in a single transaction (0x8e3016674ea8e5d2ad3af422ae5328f5a1f448e6b5a93d5d773e358bd2e440eb) at BNB Chain block 124,921,242. The attack proceeded as follows: the attacker flash-borrowed 2,656,932.60 USDT from the Moolah flash pool (0x8F73b65B4caAf64FBA2aF91cC5D4a2A1318E5D8C); used a portion to buy SKY tokens from the pair (paying a 35% buy tax, total cost approximately 435,367.43 USDT); triggered the sell-path on the acquired SKY, causing the pool controller (0xEe5fDff6364dDe0A3C66dD38A4303cDd3D10730c) to burn the pair's SKY balance and call sync(); called pair.swap() directly on the SKYDAO/USDT pair (0x096e08ddA1E18625fFdfBae4BB65a414Aa7eC2c8) to drain 183,482.88 USDT; and repaid the flash loan, retaining approximately 59,914.12 USDT in net profit. Relevant contract addresses: SKYDAO token 0x7eBa33c7a0e555D115277BA4Af04DFbB4F4Fa70c; SKYDAO/USDT pair 0x096e08ddA1E18625fFdfBae4BB65a414Aa7eC2c8.","heading":"Attack Mechanics and On-Chain Identifiers","severity":"high","sources":[{"credibility":2,"name":"DeFiHackLabs PR #1286 — SKYDAO exploit PoC with on-chain addresses and tx hash","type":"on_chain","url":"https://github.com/SunWeb3Sec/DeFiHackLabs/pull/1286"}]},{"content":"According to the DeFiHackLabs PR description, this exploit shares the same burn-from-pair + premature sync vulnerability class as at least two previously documented incidents in the same repository: CashCowCoin and FHToken (see also DeFiHackLabs PR #1279 for the FHToken PoC). The recurring nature of this pattern across multiple BSC tokens with fee-on-transfer or sell-tax mechanics suggests a broader class of design risk in protocols that allow a controller to modify pair reserves mid-transfer and call sync() before the transfer settles.","heading":"Exploit Pattern — Prior Art","severity":"medium","sources":[{"credibility":2,"name":"DeFiHackLabs PR #1279 — FHToken sell-tax reserve mismatch via premature sync (same vulnerability class)","type":"research","url":"https://github.com/SunWeb3Sec/DeFiHackLabs/pull/1279"},{"credibility":2,"name":"DeFiHackLabs PR #1286 — SKYDAO PoC noting CashCowCoin and FHToken prior art","type":"research","url":"https://github.com/SunWeb3Sec/DeFiHackLabs/pull/1286"}]},{"content":"A third-party post-mortem for the SKYDAO/USDT pair drain was published on October 5, 2026 in the RealSpap/onchain-postmortems GitHub repository (maintainer: Spap, @RealSpap on X). This repository is an independent collection of on-chain forensic reconstructions and is not affiliated with the SKYDAO team. As of October 7, 2026, no official post-mortem, security disclosure, or patch confirmation has been identified from the SKYDAO project itself. The @SkyDAO_Trust X account (linked to skydao.com) showed no public posts addressing the September 30 exploit as of the investigation date.","heading":"Third-Party Post-Mortem Documentation","severity":"medium","sources":[{"credibility":3,"name":"RealSpap/onchain-postmortems — SKYDAO/USDT Pair Drain release (October 5, 2026)","type":"research","url":"https://github.com/RealSpap/onchain-postmortems/releases/tag/incidents-2026-10-05"},{"credibility":3,"name":"Neo SKYDAO (@SkyDAO_Trust) on X — no exploit-related posts observed","type":"social_media","url":"https://x.com/SkyDAO_Trust"}]},{"content":"The SKYDAO exploit occurred within a particularly active month for crypto security incidents. According to Nominis and other tracking sources, September 2026 saw approximately $766–776 million stolen across approximately 48 major incidents, making it the highest monthly loss total of 2026. SKYDAO's $183,483 loss was a small fraction of monthly losses but is one of 14 smart contract vulnerability incidents catalogued for the month. The largest single incidents involved Bitget ($387.5M) and Liquid Network ($320M). The Nominis report classified SKYDAO as a protocol logic flaw, specifically a swap logic flaw on BSC.","heading":"Broader September 2026 Exploit Context","severity":"low","sources":[{"credibility":2,"name":"Nominis Monthly Report — Crypto Exploits and Attacks in September 2026","type":"news_article","url":"https://www.nominis.io/insights/nominis-monthly-report-crypto-exploits-and-attacks-in-september-2026"},{"credibility":2,"name":"Blockfence — September Crypto Exploit Losses Top $766M, Highest Monthly Total of 2026","type":"news_article","url":"https://blockfence.io/september-crypto-exploit-losses-top-766m-highest-monthly-total-of-2026"}]}],"sources_used":[{"credibility":2,"name":"DeFiHackLabs PR #1286 — Add SKYDAO exploit PoC (burn-from-pair + premature sync, ~59.9k USDT on BSC)","type":"research","url":"https://github.com/SunWeb3Sec/DeFiHackLabs/pull/1286"},{"credibility":2,"name":"DeFiHackLabs — SKYDAO_exp.sol (Foundry PoC with on-chain addresses and tx hash)","type":"on_chain","url":"https://github.com/SunWeb3Sec/DeFiHackLabs/blob/main/src/test/2026-09/SKYDAO_exp.sol"},{"credibility":2,"name":"Nominis Monthly Report — Crypto Exploits and Attacks in September 2026","type":"news_article","url":"https://www.nominis.io/insights/nominis-monthly-report-crypto-exploits-and-attacks-in-september-2026"},{"credibility":2,"name":"DeFiHackLabs PR #1279 — FHToken sell-tax reserve mismatch via premature sync (same vulnerability class)","type":"research","url":"https://github.com/SunWeb3Sec/DeFiHackLabs/pull/1279"},{"credibility":3,"name":"RealSpap/onchain-postmortems — SKYDAO/USDT Pair Drain release (October 5, 2026)","type":"research","url":"https://github.com/RealSpap/onchain-postmortems/releases/tag/incidents-2026-10-05"},{"credibility":2,"name":"Blockfence — September Crypto Exploit Losses Top $766M, Highest Monthly Total of 2026","type":"news_article","url":"https://blockfence.io/september-crypto-exploit-losses-top-766m-highest-monthly-total-of-2026"},{"credibility":3,"name":"Neo SKYDAO (@SkyDAO_Trust) on X","type":"social_media","url":"https://x.com/SkyDAO_Trust"},{"credibility":2,"name":"DeFi Hacks and Exploits Database — DefiLlama","type":"research","url":"https://defillama.com/hacks"}],"summary":"SKYDAO is a BSC-based token project whose SKYDAO/USDT PancakeSwap V2 liquidity pair was drained of approximately $183,483 on September 30, 2026 via a flash loan attack that exploited a premature sync() call in the token's sell-tax logic. The exploit has been reproduced in a public DeFiHackLabs proof-of-concept, and as of October 7, 2026, the SKYDAO team has not issued an official post-mortem or confirmed any patch.","timeline":[{"date":"2026-09-30","event":"SKYDAO/USDT PancakeSwap V2 pair drained of 183,482.88 USDT via burn-from-pair + premature sync() exploit on BNB Chain (block 124,921,242). Attacker netted approximately 59,914.12 USDT after repaying 2,656,932.60 USDT Moolah flash loan.","source":"DeFiHackLabs PR #1286 (on-chain PoC)","source_url":"https://github.com/SunWeb3Sec/DeFiHackLabs/pull/1286"},{"date":"2026-10-02","event":"DeFiHackLabs PR #1286, adding a public Foundry proof-of-concept reproducing the SKYDAO exploit, merged into the SunWeb3Sec/DeFiHackLabs repository.","source":"DeFiHackLabs PR #1286","source_url":"https://github.com/SunWeb3Sec/DeFiHackLabs/pull/1286"},{"date":"2026-10-05","event":"Third-party on-chain post-mortem for the SKYDAO/USDT pair drain published in RealSpap/onchain-postmortems repository (not an official SKYDAO team communication).","source":"RealSpap/onchain-postmortems GitHub releases","source_url":"https://github.com/RealSpap/onchain-postmortems/releases/tag/incidents-2026-10-05"},{"date":"2026-10-07","event":"As of this investigation date, no official post-mortem, patch confirmation, or public statement from the SKYDAO team has been identified. The @SkyDAO_Trust X account showed no exploit-related posts.","source":"AVOID.NET investigation (search of public sources)","source_url":"https://x.com/SkyDAO_Trust"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 26f25179-1680-405e-8cee-457331aa2cd3
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.