Sneaky Sandwich Exploit: The BabyDoge Attack Caused 442 BNB Loss

리서치 사고 분석
Sneaky Sandwich Exploit: The BabyDoge Attack Caused 442 BNB Loss

Project name: Baby Doge

Project type: Token

Date of exploit: Jun 21, 2023

Asset loss: 442 BNB

Vulnerability: Sandwich attack

Date of audit report publishing: Nov 16th, 2021

Conclusion: The issue was identified by CertiK but fell outside of the audit scope

Details of the Exploit

Background

BabyDoge coin is a deflationary token that charges fees during token transfers, and a proportion of fees will be added as liquidity to the BabyDoge/BNB pool.

Nature of the Vulnerability

The vulnerability involved a sandwich attack targeting the add liquidity operation, vulnerable to arbitrage if slippage isn't configured. Typically, transfer fees make such attacks unprofitable.

However, BabyDoge's fee exemption for a specific contract lets attackers transfer large Babydoge token amounts fee-free(without paying the tx fee), turning the exploit profitable.

CertiK Audit Overview

Screenshot 2024-01-08 at 5.15.22 AM Screenshot 2024-01-08 at 5.15.22 AM

Conclusion

On Jun 21, 2023, BabyDoge was attacked, leading to a loss of 442 BNB. The attacker made use of a contract that could waive the fee and performed a sandwich attack. The vulnerability lies in a manual operation that excluded a third-party contract from the fee, thus making the sandwich attack exploitable.

관련 블로그

CertiK Intel3D H1 2026 Wrench Attacks
새로운 · Report Review ·Intel3D

CertiK Intel3D H1 2026 Wrench Attacks

52 verified wrench attacks and $124.1 million in recorded exposure in H1 2026: a 33.3% rise in incidents, an 11.8-fold rise in losses, and a threat that has narrowed into a Western European crisis.

JaredFromSubway MEV bot Incident Analysis

JaredFromSubway MEV bot Incident Analysis

On 20 June 2026, the JaredFromSubway MEV bot lost 4,424 ETH (~$7.5M) due to an approval hijacking flaw. The attacker deployed fake arbitrage pools and bait tokens that appeared to offer profitable trading opportunities, causing the bot’s automated strategy to interact with malicious contracts and grant token approvals.

SOF/LAXO Incident Analysis

SOF/LAXO Incident Analysis

In February 2026 two separate exploits occurred on the BNB Smart Chain (BSC), affecting SOF and LAXO tokens, leveraging the same class of vulnerability: a flawed token burn mechanism that allowed price manipulation within a single transaction.