Skip to main content
AVOID.NET

Audit log

Every state-changing event for SKYDAO Premature Sync Exploit (September 2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-10-07 12:17:55Z
    Score: ? → ? (no score change)
    anchorfailed
    chain
    ●—
    hash
    2HSWm7qhL3ff…wW3VTiccsha256 → base58
    verifying row…
    canonical bytes (7133 B) ▸
    {"actor":"system:backfill","investigation_id":"d77556bb-a35d-47e1-b5f8-bbbbf0184ae1","kind":"publish","page_slug":"skydao-premature-sync-exploit-september-2026","published_at":"2026-10-07T12:17:54.938Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"SKYDAO Premature Sync Exploit (September 2026)","sections":[{"content":"According to a proof-of-concept submitted to the DeFiHackLabs GitHub repository, the SKYDAO token's sell-tax mechanism applied an alleged 35% tax on sales, routing the gross sale amount to a separate pool controller contract before the PancakeSwap V2 pair received the seller's net 65%. The controller allegedly then sold the taxed portion, burned the pair's entire SKYDAO token balance, and called the pair's sync() function before the net transfer to the pair had settled. This sequence allegedly locked in an artificially low recorded reserve while a token transfer was still in-flight. Once the actual balance later arrived, the pair's recorded reserve was stale, which allegedly allowed a directly-called pair.swap() to drain USDT against the outdated reserve figure. The proof-of-concept states the sell path had no owner or admin access controls, making it exploitable by any user who could structure the correct sequence of calls.","heading":"Alleged Attack Vector: Burn-From-Pair and Premature Sync","severity":"critical","sources":[{"credibility":2,"name":"SunWeb3Sec/DeFiHackLabs PR #1286 — SKYDAO exploit PoC (burn-from-pair + premature sync)","type":"research","url":"https://github.com/SunWeb3Sec/DeFiHackLabs/pull/1286"}]},{"content":"The DeFiHackLabs proof-of-concept describes the attack as a single flash-loan transaction on BNB Chain. The attacker allegedly flash-borrowed 2,656,932.60 USDT, used part of it (435,367.43 USDT, inclusive of an alleged 35% buy tax) to purchase SKYDAO tokens, triggered the sell-path mechanism that burned the pair's token balance and called sync() prematurely, then executed a direct pair.swap() call to drain USDT from the pair at the stale reserve figure before repaying the flash loan. The PoC's source file states the pair \"loses its entire 183,482.88 USDT reserve\" and that the attacker netted approximately 59,914.12 USDT in profit after repaying the loan and associated costs. The PoC identifies a specific on-chain transaction hash, attacker address, SKYDAO token contract, pool-controller contract, and SKYDAO/USDT pair address as supporting evidence. A dexscreener listing for a BSC pair at the same address cited in the PoC (0x096e08dda1e18625ffdfbae4bb65a414aa7ec2c8) independently corroborates the existence of an active SKYDAO/USDT PancakeSwap pair, though it does not itself confirm the exploit.","heading":"Alleged Attack Sequence and Financial Loss","severity":"high","sources":[{"credibility":2,"name":"SunWeb3Sec/DeFiHackLabs PR #1286 — SKYDAO exploit PoC (burn-from-pair + premature sync)","type":"research","url":"https://github.com/SunWeb3Sec/DeFiHackLabs/pull/1286"},{"credibility":2,"name":"SKYDAO/USDT pair on PancakeSwap (BSC) — Dexscreener","type":"on_chain","url":"https://dexscreener.com/bsc/0x096e08dda1e18625ffdfbae4bb65a414aa7ec2c8"}]},{"content":"As of this investigation, the SKYDAO incident has not been independently confirmed by Tier 1 regulatory, court, or major news sources, nor by Tier 2 crypto-native outlets (CoinDesk, The Block, Decrypt) that this investigation could locate through search. A broader industry report covering crypto exploits in September 2026 (Nominis) documents a structurally similar \"burn-from-pair and sync()\" attack that same month against a different BSC token (RWC), which lost approximately $109,461 — indicating that this attack pattern was being exploited against multiple low-cap BSC tokens around the same period, but this report does not specifically name or corroborate SKYDAO. Readers should treat the SKYDAO loss figures and attack narrative as sourced to a single technical proof-of-concept repository rather than to multiple independently-verifying outlets, and the overall confidence of this write-up is accordingly limited.","heading":"Limited Independent Verification","severity":"medium","sources":[{"credibility":2,"name":"Nominis Monthly Report — Crypto Exploits and Attacks in September 2026","type":"research","url":"https://www.nominis.io/insights/nominis-monthly-report-crypto-exploits-and-attacks-in-september-2026"}]},{"content":"No official post-mortem, incident disclosure, or confirmed contract patch attributable to a SKYDAO team could be identified through web search as of this investigation. Searches for a SKYDAO project website, official social media account, or team identity associated with the token also did not return verifiable results, consistent with the profile of a small, low-liquidity BSC token with minimal public-facing infrastructure. The lack of any identifiable team communication or security audit history is itself a risk indicator, independent of the specific exploit allegations, and should be weighed accordingly.","heading":"Absence of Project Response or Patch Confirmation","severity":"medium","sources":[{"credibility":2,"name":"SunWeb3Sec/DeFiHackLabs PR #1286 — SKYDAO exploit PoC (burn-from-pair + premature sync)","type":"research","url":"https://github.com/SunWeb3Sec/DeFiHackLabs/pull/1286"}]}],"sources_used":[{"credibility":2,"name":"SunWeb3Sec/DeFiHackLabs PR #1286 — SKYDAO exploit PoC (burn-from-pair + premature sync)","type":"research","url":"https://github.com/SunWeb3Sec/DeFiHackLabs/pull/1286"},{"credibility":2,"name":"SKYDAO/USDT pair on PancakeSwap (BSC) — Dexscreener","type":"on_chain","url":"https://dexscreener.com/bsc/0x096e08dda1e18625ffdfbae4bb65a414aa7ec2c8"},{"credibility":2,"name":"Nominis Monthly Report — Crypto Exploits and Attacks in September 2026","type":"research","url":"https://www.nominis.io/insights/nominis-monthly-report-crypto-exploits-and-attacks-in-september-2026"}],"summary":"SKYDAO was a low-liquidity token on Binance Smart Chain, paired with USDT on PancakeSwap V2, whose sell-tax logic contained an alleged \"burn-from-pair plus premature sync()\" flaw. On September 30, 2026, an attacker allegedly used a flash loan to exploit this flaw, draining the pair's entire USDT reserve and netting roughly $60,000 in profit from an approximately $183,000 reserve loss. The incident is documented primarily through a public proof-of-concept submitted to the DeFiHackLabs repository, with no independent mainstream news coverage, team statement, or confirmed patch identified as of this writing.","timeline":[{"date":"2026-09-30","date_evidence":"SKYDAO (SKYDAO/USDT PancakeSwap V2) - burn-from-pair + premature sync() reserve mismatch - BNB Chain, 2026-09-30. Attacker nets 59,914.12 USDT","event":"Attacker allegedly flash-borrows 2,656,932.60 USDT, exploits SKYDAO's sell-tax burn-and-sync logic, and drains the SKYDAO/USDT PancakeSwap pair of its 183,482.88 USDT reserve, netting approximately 59,914.12 USDT after repaying the loan.","source":"SunWeb3Sec/DeFiHackLabs PR #1286","source_url":"https://github.com/SunWeb3Sec/DeFiHackLabs/pull/1286"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 89862a0b-e6ec-478d-a0a1-da23cada4630
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.