The incident was driven by a “double counting” flaw that distorted token balances. This allowed the attacker to profit without breaking the platform’s normal operating logic.

Dangerous burn: how Movie Token handed $242K to an attacker

25.03.2026

269

3 min

On March 10, 2026, Movie Token (MT) was exploited, allowing an attacker to drain roughly $242,000 due to a critical flaw in the token sale logic. GetBlock AML Research analyzed the exploit step by step, revealing how a coding error led to the loss of funds.

The issue stemmed from a “double counting” bug. When users sold MT, the system both sent the tokens to a liquidity pool and simultaneously marked the same tokens for future burning. Later, when the daily rewards function (distributeDailyRewards) was triggered, those tokens were burned, artificially reducing supply. This drove the price of MT sharply higher — a condition the attacker exploited to extract funds from the pool.

Addresses Involved

Attacker wallet:
0xDB0901A3254f47c0CE57fFFCE2C730Bc33A1c0e1
Victim address:
0xb32979f3A5b426a4A6Ae920f2B391D885Abf4C18

Step-by-Step Breakdown of the Attack

The attacker began by taking out a flash loan of 358,681.54 WBNB, effectively using all available liquidity from a single source.

Next, they executed a series of swaps: buying a small amount of MT, adding liquidity to the pool, and receiving LP tokens representing their share. They then swapped 496 WBNB for 10 million MT, sending the tokens into the exchange system.

After that, they removed the previously added liquidity and reclaimed the same 10 million MT. This workaround helped bypass fees and restrictions that would apply to direct purchases.

The attacker then initiated another flash loan operation. Within it, about 90% of the tokens (after fees) were sent to the pool — while simultaneously being recorded as tokens to be burned later.

They then swapped 717 WBNB for roughly 10 million MT, significantly reducing the token supply in the pool. Afterward, they manually triggered the reward distribution function, which burned about 6.74 million MT directly from the pool.

As a result, the pool was left with very few MT tokens (around 21,000) but still held a large amount of WBNB (~1,201). This imbalance caused a sharp price spike. The attacker then swapped their ~10 million MT for 1,198.628 WBNB, capitalizing on the distorted price. After repaying the loan, they walked away with a profit of 381.7468 WBNB.

Root Cause of the Vulnerability

The core issue was a flaw in the token sale logic. When tokens were sold, the system:

  • Sent them to the liquidity pool
  • Simultaneously marked them as “to be burned”

Later, those same tokens were burned again, effectively double-counted and removed from circulation. Based on the code structure, this appears to have been an unintended implementation error.

What Happened to the Funds

Transaction showing the swap of stolen assets via Railgun

After the exploit, the attacker swapped 381.7468 WBNB for $242,000 in USDC. The funds were then bridged to another network and converted into DAI. Finally, the attacker used Railgun, a privacy tool, to further obfuscate the transaction trail.

Subscribe to Getblock Magazine and stay up to date with the latest news from the world of cryptocurrencies and the digital economy