SlowMist: Little Boy Plus hacked, causing approximately $378,000 in damages.

This article is machine translated
Show original

Little Boy Plus was hacked, resulting in losses of approximately 377,642 USDT , equivalent to 610,555 BNB.

SlowMist reported that the vulnerability lies in the _update function within the LBPHashrate contract. This function can be triggered via a transferFrom command with a value of 0, thereby bypassing OpenZeppelin's permission checking mechanism.

An attacker can call this function without granting permissions, trigger _harvest , and send the Mint Token LBP to the PancakePair address via LBP.mintReward .

The Mint LBP increases the pool balance but does not change the reserves, after which the attacker withdraws USDT via the PancakePair.swap command.

Source
Disclaimer: The content above is only the author's opinion which does not represent any position of Followin, and is not intended as, and shall not be understood or construed as, investment advice from Followin.
Like
60
Add to Favorites
10
Comments