Alert | Our monitoring system detected a weird transaction (tools.blocksec.com/tx/bsc/0xe176b…), and the "attack" profit is around 61,160 BSC-USD.
#DeFi #BSC #CryptoSecurity
2. Analysis
1) Borrow BSC-USD via flashloan, buy USDT, and swap to $Zoom @ZoomproFinance
2) Call 0x47391071824569f29381dfeaf2f1b47a4004933b "0x1e69fcc4" function and it will send 1M USDT to ZOOM/USDT Pair
2. Analysis
3) The price of Zoom/USDT will raise after calling the pair function sync
4) Swap Zoom to USDT, buy BSC-USD and return the flashloan.
3.Notes
1) The "USDT" we mentioned here is not the Tether USDT. It is not an open source address(0x62d51aacb079e882b1cb7877438de485cba0dd3f) . And it is not a standard BEP-20 token because it doesn't emit any transfer events when making transfers.
3. Notes
2) Only Pancake where the attacker borrowed the flashloan is open source among these AMMs. The ratio of BSC-USD to USDT is pegged at 1:1 in the AMM instead of a constant product.
Share this Scrolly Tale with your friends.
A Scrolly Tale is a new way to read Twitter threads with a more visually immersive experience.
Discover more beautiful Scrolly Tales like this.
