BlockSec: USDC-OCA liquidity pool on BSC chain attacked, hacker exploits deflation mechanism vulnerability to steal $422,000

BNB0,07%

PANews February 14 News, according to BlockSec Phalcon monitoring, an unknown USDC-OCA liquidity pool on the BSC chain was attacked, resulting in approximately 422,000 USDC being withdrawn. The attacker exploited a logical vulnerability in the deflationary OCA token’s sellOCA() function, which, each time it was called to swap OCA tokens, also removed an equivalent amount of OCA from the liquidity pool, artificially inflating the token’s price within the pool.

The attack was completed in three transactions: the first executed the attack operation, while the remaining two were mainly used to pay additional block builder bribes. The attacker paid a total of about 43 BNB plus 69 BNB to 48club-puissant-builder, with an estimated profit of approximately $340,000. Another transaction in the same block at position 52 failed, suspected to have been front-run by the attacker.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

BIS Warns Dollar-Denominated Stablecoins Like USDT and USDC Pose Financial Stability Risk

Gate News message, April 21 — The Bank for International Payments (BIS) has reiterated concerns about stablecoins, with Managing Director Pablo Hernandez de Cos warning that dollar-denominated stablecoins such as USDT and USDC are fundamentally riskier than commonly perceived. Cos stated that

GateNews8h ago

Whale Deploys $10M USDC on HyperLiquid, Opens Major Oil Short Positions

Gate News message, a newly created wallet address "0xEbE" deposited $10 million USDC into HyperLiquid and opened a 63,000 BRENTOIL short position with 20x leverage. Another wallet "0x9D3", linked to the same whale, holds 20x short positions of 250,000 BRENTOIL (valued at $22.5 million) and 210,000 C

GateNews15h ago

RedotPay Adds SUI and Native USDC-Sui Support, Enabling Payments in 100+ Countries

RedotPay has integrated SUI and USDC-Sui, allowing users to spend tokens and transfer funds in local fiat across 100+ countries. With 7 million users and $10 billion in annual payments, RedotPay is already profitable. The integration highlights fintech's shift towards blockchain solutions for international transactions.

GateNews17h ago

Justin Sun Deposits $55.01M USDC to Spark Protocol, Cumulative Deposits Reach $179M

Justin Sun withdrew 55.01 million USDC from a major CEX and deposited it into the Spark protocol, totaling $179 million in deposits since Aave's bad debt incident, highlighting Spark's growing liquidity.

GateNews04-20 16:01
Comment
0/400
No comments