• CONTACT
  • MARKETCAP
  • BLOG
CryptoUnfolded.com
  • BOOKMARKS
  • Home
    • Home 2
    • Home 3Hot
    • Home 4
    • Home 5New
  • News
  • Cryptocurrency
  • Tutorials
    Buy and Sell

    Buy, sell and use crypto

    Earn Crypto

    Learn and earn crypto

    Crypto Wallet

    The best self-hosted crypto wallet

  • Pages
    • Blog Index
    • Contact Us
    • 404 Page
    • Search Page
    • Customize Interests
    • My Bookmarks
Reading: DIP Exploit Drains $111K After Router Transfer Executes Twice
Share

CryptoUnfolded.com

Font ResizerAa
  • Home
  • Contact
Search
  • Demos
    • Home 1
    • Home 2
    • Home 3
    • Home 4
    • Home 5
  • Categories
    • Coinbase
    • Mining
    • Stocks
  • Bookmarks
    • My Bookmarks
    • Customize Interests
  • More Foxiz
    • Blog Index
    • Sitemap
Have an existing account? Sign In
Follow US
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
Cryptocurrency

DIP Exploit Drains $111K After Router Transfer Executes Twice

Admin
Last updated: June 17, 2026 9:38 am
Admin
Published: June 17, 2026
Share


glenn nästaglenn nästa

DIP was hit by an estimated $111,000 exploit after a flaw in its customized transfer logic allowed the same router-linked token movement to execute twice. The attacker combined the duplicated settlement with the accounting behavior of the AIC/DIP liquidity pair, drained its real DIP reserve and converted the extracted value through a related AIC/USDT pool.

The BNB Chain transaction shows a coordinated sequence involving balance preparation, a call to skim(router), reserve synchronization and reverse settlement through the compromised market.

Double Transfer Broke The Pool’s Accounting

The vulnerable path appears around nexus_dip.sol:1702. When either the sender or recipient matched the router address, DIP first executed super._transfer inside the router-specific branch. The function then continued to another unconditional transfer at the end of the same execution path.

One request could therefore settle the same amount twice. The first transfer completed the movement expected by the router, while the second removed an equal quantity without a separate economic action supporting it. That behavior broke a basic assumption used by automated market maker pairs, where one requested token transfer should create one corresponding balance change.

Attacker Set The DIP Balance To Twice The Reserve

The attacker first shaped the AIC/DIP pair until its live DIP balance equaled exactly twice its recorded reserve. If the stored reserve was represented as R, the pair held a balance of 2R, leaving an apparent surplus of R.

Calling skim(router) should have transferred only that surplus to the router. The first DIP transfer reduced the pair balance from 2R to R, which would normally leave the genuine reserve intact. DIP’s second transfer then removed the remaining R, emptying the real DIP reserve through the same call.

The attacker followed with sync(), updating the pair’s stored reserves to match the manipulated balances. This locked the distorted state into the pool’s accounting and created the conditions needed to extract value from the other side of the market.

AIC/USDT Pool Provided The Exit Liquidity

After the DIP reserve was drained and the pool was synchronized, the attacker completed reverse settlement through the AIC/DIP pair and received AIC from the compromised liquidity position. The AIC was then sold through the sibling AIC/USDT pool, turning the token-accounting failure into stablecoin-denominated proceeds.

The exploit did not depend on a flaw in skim() or sync() themselves. Both functions behaved according to normal pair accounting, while DIP’s non-standard transfer path produced two balance movements from one request. A similar market-structure risk appeared when a custom token mechanism distorted a PancakeSwap pool, allowing token-side behavior to become the route for extracting the paired asset.

Removing the second unconditional transfer is the central contract fix, but restoring safe trading also requires verifying the patched router path, rebuilding the affected liquidity and confirming that no other transfer branch can duplicate settlements. Until those steps are completed, the AIC/DIP pair remains exposed to the accounting failure that enabled the estimated $111,000 drain.

Zcash Targets Late July Ironwood Upgrade As ZEC Extends Recovery
Revolut Launches EURR Euro Stablecoin for Select European Users
CFTC Staff Pushout Raises New Questions Over Prediction-Market Oversight
Avalanche Launches Payments Collective With 28 Finance And Crypto Firms
HYPE Whale Buying Accelerates As Millions In USDC Move Into Hyperliquid

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article UNI Surges 24% As Whales And Tokenization Narrative Reignite Uniswap
Next Article CZ Praises Hyperliquid As OKX CEO Questions His Aster Ties

Follow US

Find US on Socials
FacebookLike
XFollow
YoutubeSubscribe
TelegramFollow
Subscribe to our newslettern

Get Newest Articles Instantly!

- Advertisement -
Ad image
Popular News
EtherMail launches moltmail – the AI agent email, identity and wallet solution
Here’s Why Litecoin Is Rising To The Limelight Again: Is This The Future Of Crypto Payments?
Altcoin Activity Slumps, But Bitcoin Volume Stays Resilient

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
CryptoUnfolded.com

We influence 20 million users and is the number one business blockchain and crypto news network on the planet.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

Ad image
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?