ZeroShadow details RWT exploit on BNB Smart Chain, traces roughly $118,000 in profit
ZeroShadow said it detected an attack against RWT on BNB Smart Chain on July 19, 2026, with estimated losses of about $118,000. According to the firm’s breakdown, the attacker borrowed 1,000,000 USDT via a flash loan from Lista DAO: Moolah, bought RWT through a privileged trading contract, then repeatedly sold the token in a way that triggered additional burns from the RWT/USDT PancakeSwap V2 pair. The key issue, ZeroShadow wrote, was not simply a burn function with elevated authority. Instead, the RWT project had granted burn permissions to a public-facing trading contract whose sell function could be called by ordinary users. After each sale, that contract allegedly burned roughly twice the amount sold from the pair itself and then called sync(), shrinking the pair’s RWT reserves while leaving USDT reserves largely unchanged and pushing the pool price higher. The report also noted that the project sent two setRole transactions about six minutes after the attack to revoke the trading contract’s role. After repaying the flash loan, the attacker transferred 118,069.281571404198479027 USDT to the attacker address, leaving an estimated profit of about $118,000.


