CCC, also known as CashCowCoin, suffered an estimated $117,000 exploit on BNB Smart Chain on Aug. 28, 2026, after an attacker abused the token contract’s sell() function to burn CCC tokens held in its liquidity pool.
Blockchain security firm TenArmorAlert said its monitoring system detected suspicious activity involving CCC on BSC and traced the incident to the sell() function. The firm linked the activity to abnormal movement in the token’s price and identified an attack transaction beginning with 0x89d805064, though it did not publish a complete breakdown of the assets removed or the attacker’s final proceeds.
Separate reporting described the flaw as a vulnerability in the trading router implementation, claiming attackers could drain reserves repeatedly through the PancakeSwap Router. The affected trading pair was identified as CCC/WBNB, raising concerns for liquidity providers. CashCowCoin reportedly faced zero trading volume in the 24 hours following the alert.
No detailed post-mortem, fund recovery plan, or compensation proposal had been announced at the time of the alert. TenArmorAlert has not explained how the attacker obtained the ability to trigger the affected function or whether access controls were bypassed.
The incident follows several contract exploits on BNB Chain in recent months, including the Swan Treasury loss of $625,000, Balance Coin's $915,000 attack, Token of Power's $1.58 million Balancer pool exploit, DxSale's $7.3 million backdoor incident, and SafeMoon's $8.9 million burn function exploit in March 2023.