A liquidity pool on BNB Chain was exploited, resulting in a loss of approximately $1.11 million.
AMBCrypto
2h ago
Ai Focus
The OLPC/LABUBU pool on the BNB Chain was exploited, with attackers using distorted reserves to withdraw LABUBU at a low price, resulting in a loss of approximately $1.11 million.
Helpful
No.Help

On June 20, the OLPC/LABUBU liquidity pools on BNB Chain were compromised, with attackers transferring approximately $1.11 million in assets from the PancakeSwap V2 pools. The key issue wasn't typical flash loans, but rather a discrepancy between the pool's reserve data and the actual balance, leading to price distortion.

The attack point lies in the disconnect between reserves and balance.

This incident involves the deflationary mechanism of the OLPC token. Analysis shows that the attacker first initiated a small transfer via a contract, subsequently triggering the destruction of tokens in the pool. During the process, approximately 51.9 million OLPC and 124,000 LABUBU were transferred to the destruction address.

The problem is that the reserve values cached for the trading pair are not updated synchronously, but the actual token balance in the pool has clearly decreased. This disconnect between reserves and balance leads to a distorted price from the constant product market-making mechanism, creating opportunities for subsequent arbitrage.

Attackers withdraw remaining liquidity at a low price

After the price was manipulated, the attackers were able to buy and drain the remaining LABUBU liquidity from the pool at a price significantly lower than normal, thus profiting from the transaction. The report noted that, as of press time, the stolen funds had not been transferred across chains, nor had they flowed into Tornado Cash or been dispersed to multiple addresses.

Currently, it remains unclear whether this vulnerability was intentionally planted beforehand. However, preliminary analysis points to the decimalsValue parameter in the OLPC contract as the cause of the problem.

Abnormal parameters may have been the cause of problems 46 days ago.

Further on-chain analysis revealed that approximately 46 days prior to the attack, the OLPC token owner changed `decimalsValue` from 1 to an unusually large value. This change likely caused the `_update()` function to trigger excessive destruction, thus setting the stage for this reserve distortion.

It's worth noting that this parameter had already been set to an abnormal level several weeks before the project relinquished ownership of the contract. This has led to suspicions that the vulnerability may have existed long before the attack.

Additional information:According to DeFiLlama data, cumulative losses from various crypto attacks since June have risen to approximately $60.03 million. During the same period, Humanity Protocol suffered losses of approximately $32 million, and Aztec Network also experienced an attack, losing 1,158 ETH, 150,000 DAI, and 0.4696 renBTC.

Tip
$0
Like
0
Save
0
Views 546
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Aztec Network's overpass was exploited, resulting in a loss of approximately $2.16 million.
Aztec Network's Private Rollup Bridge was exploited, with on-chain data showing a loss of approximately $2.16 million, involving ETH, DAI, and renBTC.
U.Today
·2026-06-18 20:21:15
916
Aztec suffered its second attack in a week, resulting in losses of approximately $2.15 million.
Aztec suffered its second attack in a week, with old payment product contracts being exploited by forged rollup credentials, resulting in a loss of approximately $2.15 million.
Coinpaper
·2026-06-18 21:31:06
393
Ethereum's well-known mezzanine bot was exploited, resulting in a $7.5 million loss.
The well-known Ethereum MEV bot jaredfromsubway.eth was found to have over $7.5 million stolen after approving a fake transaction path; some of the funds subsequently flowed into Tornado Cash.
CoinDesk
·2026-06-21 15:24:43
767
Jared from Subway MEV robot attacked, resulting in approximately $7.5 million in losses.
AMBCrypto reports that the Jaredfromsubway.eth-related MEV bot was attacked, resulting in a loss of approximately $7.5 million, exposing permission security risks in DeFi automated trading.
AMBCrypto
·2026-06-21 19:23:58
129
Aztec's old contract suffered two attacks within three days, resulting in losses exceeding $4 million.
Aztec's two deactivated old contracts were attacked twice within three days, resulting in a total loss of over $4 million. The current network and AZTEC tokens are unaffected.
CoinJournal
·2026-06-18 20:30:00
455