link.png

ID:

lpc-token-990

Date:

Status:

Incident Count:

July 25, 2022

Verified

1

info.png
target.png
REKT

Contributor:

chain.png

web3rekt.com

KYC By:

KYC:

No

info.png

Audit By:

Audits:

None

Loss Amount:

45,000

info.png

Recovered:

-

Rewards:

Currency:

USD, LPC

info.png

Key Indicators

Platform:

Type:

Category:

Method:

Data Sources:

Binance Smart Chain

Assets

Token

Flash Loans

Extended Method:

Logic error, _transfer function is not updated.

info.png

Days in Operation:

184

(0.50 Years)

chain.png
chain.png
chain.png
chain.png
datasource.png

Beosin Alert reported that LPC token was under a flash loan attack that netted the attacker $45k.

The attacker first borrowed 1,353,900 $LPCs via flashloan from Pancake, then called the _transfer function in the LPC contract to transfer to himself.

Since the ledger balance is not updated in the _transfer function, but is modified directly on the original recipientBalance, resulting in an increase in the attacker balance.

The attacker then repays flashloan and converts the obtained $LPCs to $BNB, making a total profit of ~$45,715

info.png

DISCLAIMER: While web3rekt has used the best efforts in aggregating and maintaining this database, this web site makes no representations or warranties with respect to the accuracy or completeness of its information and data herein, and specifically disclaim any implied warranties of merchantability or fitness for any particular purpose. 

Under no circumstances, shall web3rekt be liable for any loss of profit or funds, any regulatory or governmental penalties, any legal costs, or any other commercial and non-commercial damages, including but not limited to special, incidental, consequential, or other damages from any or all usage of the data and information derived from this database.