Preview surface — demo data. Where real data exists today (e.g. RealT, BlackRock BUIDL, Lift Dollar) we render it; everywhere else we render synthetic enrichment generated deterministically from public signal and clearly marked Demo or Inferred. The Phase 3 roadmap replaces every synthetic source with live ingestion — see Methodology → Exposure Graph & Similarity Engine.
← back to incident ledger

signature malleabilityDemo

Sep 17, 2022 · $656.7K · protocol

Narrative

On 2022-09-17, PancakeSwap suffered a signature malleability incident resulting in approximately $656,747 in losses. The exploit targeted the protocol layer. A flash loan was used to amplify the attack. Attribution: whitehat. This is a demonstration entry — not a real incident.

Classification

Root cause
signature_malleability
Secondary causes
Attack layer
protocol
Strategy
tech_vuln
Actor role
target
Attribution
whitehat
Attacker address
Flash loan
yes
Audited at time
yes
Bounty at time
yes

AADAPT mappings

DEMO:AADAPT.TA0004DEMO:AADAPT.T1190

Evidence

Disclosure date
Sep 17, 2022
Funds recovered
Audit firms at time
Certora, Trail of Bits
Post-mortem URLs (synthetic)
  • https://medium.com/pancakeswap/post-mortem-pancakeswap-2022-09-17
  • https://rekt.news/pancakeswap-rekt
  • https://blog.pancakeswap.xyz/incident-report
tx hashes (3)
  • 0x51301316401905645ec25f0bf14f6cf5c5847dc25cfc482412b2baa3ae6dfdf8
  • 0xfd33b1a6857c8d104c690918591cf0c1d2d8faab636a4ef9f4d0d54165c2cd58
  • 0x8e3c04ad3f0962ce716a2de598e29f20eab51a85be83d39c03cc5d31b0bfe50d