
DIP Token bug drains $111K from pool
- A coding flaw in the DIP token allowed an attacker to drain approximately US$111,098 in USDC from a liquidity pool.
- SlowMist said a missing return statement in the token’s transfer function caused certain transfers to execute twice.
- The incident adds to a growing list of DeFi exploits as losses across the sector have exceeded US$1 billion in 2026.
DIP Token (CRYPTO:DIP), a utility token within the Etherisc ecosystem, suffered an exploit that allowed an attacker to drain approximately US$111,097.60 in USD Coin (CRYPTO:USDC), according to blockchain security firm SlowMist.
The exploit occurred because the token’s function lacked a return statement in the code path used for PancakeSwap router transactions.
“The attacker exploited this by calling to trigger double DIP transfers, then to set the DIP reserve to an extremely low value, manipulating the AMM price to drain the pool,” said SlowMist.
The security firm said the flaw caused certain transfers to execute twice instead of once, allowing funds to be repeatedly extracted from the affected liquidity pool.
The attacker has not been identified and no recovery of the stolen US$111,097.60 has been confirmed, while the DIP token price reaction was not immediately disclosed.
SlowMist said decentralised exchange routers frequently interact with customised token transfer logic, creating additional risks when projects modify standard token templates.
The incident follows a series of decentralised finance security failures in 2026, with industry losses from hacks and exploits exceeding US$1 billion and SlowMist recording more than 2,150 security incidents in its public database.