Subscribe for notification
Crypto

Hacker Siphons $1.4 Million From CUT Token Pools

Without burning the corresponding LP tokens, an account was able to remove 1.4 million BSC-USD through the use of an unreadable function.

A blockchain security platform Certik report states that on September 10, an attacker went through a liquidity pool containing CUT tokens and took roughly $1.4 million worth of Bows Coin Synthetic US Dollar (BSC-USD). The “future yield” element of the CUT token contract was set by another unconfirmed contract, which was also utilized to drain the BSC-USD in an unidentified manner.

CertiK reported the occurrence on X.

Source: Certik.

The exploited CUT token may be found on the Binance Smart Chain at an address that ends in 36a7. It is not to be confused with the Crypto Unity project, which uses a different address but the same ticker symbol. The pancake swap exchange included the emptied pool. It doesn’t have impacted any other Pancakeswap pools.

According to blockchain data, the attacker used four transactions to empty the BSC-USD pool. A total of $1,448,974 was subtracted.

CUT exploit transactions. Source: BSCScan.

Since the attacker had not previously deposited money into the pool and had no liquidity provider tokens, it seems doubtful that this withdrawal was authorized.

The attacker called a function called “0x7a50b2b8” in each transaction. However, the token contract does not mention it. The report states that this suggests the attacker had to invoke ILPFutureYieldContract(), which allows the user to invoke a different function on an entirely other contract whose address ends in 1154. BSC Scan only reveals an illegible bytecode for this unconfirmed contract.

Separate contract used in CUT exploit. Source: BSCSCan.

One significant way that Web3 users lose money is through exploits. On September 3, a Penpie decentralized finance protocol exploit resulted in the loss of nearly $25 million worth of cryptocurrency. On August 6, an attacker used a flawed deployment script to siphon $10 million from the bridge of the Ronin gaming network. In this instance, the exploit has left CUT liquidity providers with a combined loss of $1.4 million.

Ruth Okarter

Ruth is a seasoned news reporter and editor who brings her sharp eye and passion for storytelling to Protechbro.com. With a background in English and literary studies, Ruth crafts compelling narratives that unpack the complexities of the ever-evolving tech landscape.

Disqus Comments Loading...

Recent Posts

Hamster Kombat Introduces Earn Benefits on Telegram Wallet

The trending P2E game Hamster Kombat has introduced a new way for users to earn more for those who withdraw…

2 hours ago

Amazon Releases Video Generator Only for Ads

Like Google, Amazon has released an AI-powered video generator, but it can only do a few things at a time…

6 hours ago

Upchieve Launches Free Tool for Teachers

Upchieve, a free app offering 24/7 college counseling and tutoring for low-income students, introduces a new tool to support teachers…

7 hours ago

Hong Kong to Launch Ethereum ETF Staking by Year-End

The crypto regulators in Hong Kong may launch Ethereum ETF staking by the end of 2024, which could likely give…

7 hours ago

US SEC Seeks Coinbase Lawsuit Discovery Extension

The US SEC is seeking a Coinbase lawsuit discovery extension as they have reached an agreement with Coinbase to shift…

8 hours ago

Worldcoin Launches Face Auth Technology

Worldcoin, a global digital identity and cryptocurrency initiative, has introduced Face Auth, a new security measure for the World ID…

8 hours ago