PancakeSwap V2 platform has recently suffered a significant loss in a $OLPC/$LABUBU pool. Particularly, the attacker targeting $OLPC/$LABUBU pool on PancakeSwap has drained a total of $1.1M. As per the data from PeckShieldAlert, the exploiter drained the respective funds from the BNB Chain. Additionally, to launder the exploited capital, the attacker used Tornado Cash.
#PeckShieldAlert An OLPC/LABUBU pool on PancakeSwap on #BNBChain has been exploited, resulting in a loss of ~$1.1M.
The exploiter bridged the stolen funds to #Ethereum, deposited 633.4 $ETH into #TornadoCash, and sent 0.0221 $BNB and 0.0411 $ETH to a dead address. pic.twitter.com/lCDWwThsjH
— PeckShieldAlert (@PeckShieldAlert) June 20, 2026

Exploiter Attacks PancakeSwap-Based $OLPC/$LABUBU Pool, Draining $1.1M From BNB Chain
Based on the market data, the recent exploit of the $OLPC/$LABUBU pool on PancakeSwap has led to the drainage of up to $1.1M in funds from the BNB Chain. For this purpose, the attacker bridged the drained funds to Ethereum ahead of depositing 633.4 $ETH into the Ethereum-based privacy protocol Tornado Cash. Along with laundering the capital via the privacy mixer, the attacker also transacted 0.0411 $ETH and 0.0221 $BNB to a dead address.
Hence, the attacker efficiently burned the exploited tokens. Keeping this in view, the exploit underscores the persistent vulnerabilities in the infrastructure of decentralized exchanges in the case of interaction with burn-on-transfer or deflationary tokens. This attack adds to the expanding list of huge DeFi exploits seen during this year, highlighting the urgent requirement for enhanced security measures across digital asset liquidity pools.
The analysis also points out that a nearly 10 $OLPC transaction routed via the exploiter’s contract triggered the attack. The activity paved the way for the burning of up to 124K $LABUBU and 51.9M $OLPC tokens to a dead address at “0xed…f365.” While the $OLPC/$LABUBU pair saw a balance crash, the cached reserves thereof were not resynchronized. This desynchronization permitted the attacker to perform the exploit.
$OLPC Sees Extreme Swings After Exploit
According to PeckShieldAlert, the exploiter swept the $LABUBU side as well as routed it via $WBNB/$USDT and $LABUBU/$WBNB pools. As a result, the attacker quit with almost 1,115,903 $USDT. Specifically, the $OLPC token experienced a notable crash to $3.89 ahead of a staggering spike to $4,190. This denotes a 6,839% rise before a swift correction. Overall, the $OLPC/$LABUBU exploit on PancakeSwap reflects the persistent risk present in diverse DeFi protocols, indicating the need for proactive monitoring and stringent smart contract auditing for on-chain activity.

