On 20 June, the OLPC/LABUBU mobile pool on BNB Chain was used and the attackers transferred approximately $11.11 million of assets from the PancakeSwap V2 related pool. The crux of the event was not a regular lightning loan, but a deviation between the pool reserve data and the real balance, leading to distortions in prices.
The point of attack is out of proportion to the balance.
The incident involved deflation mechanisms for OLPC tokens. The analysis revealed that the assailants initiated a small transfer through a contract and then triggered the destruction of the pool coin. In the process, approximately 51.9 million OLPCs and 124,000 LABUBUs were transferred to destruction sites.
The problem is that the trade has not been synchronized to update the value of the cache reserve, but the real currency balance of the pool has been significantly reduced. Following a disconnect between reserves and balances, the mechanism for marketing the constant product product gives unrealistic prices and leaves room for subsequent arbitrage.
The attackers took the remaining liquidity at low cost.
Following price erosion, the attackers were able to buy and drain the remaining LABUBU liquidity in the pool at prices that were clearly below normal levels, thus making a profit. It was mentioned that stolen funds had not been transferred across the chain at the time of the submission, nor had they reached Tornado Cash or dispersed to multiple addresses.
At present, it is not possible to confirm whether this loophole has long been buried. However, the preliminary analysis points to the parameters of the OLPC contract for decimalsValue.
Anomalous parameters or infestation 46 days ago.
More in-depth chain analysis shows that approximately 46 days before the attack, the OLPC token owner had changed decimalsValue from 1 to an unusually large number. This change makes it possible for the update() function to trigger excessive destruction, thus placing the condition for this stock's distortion.
It is noteworthy that this parameter was set at an abnormal level in the weeks before the project relinquished contractual ownership. This also casts doubt on the fact that the deficiencies may have existed well before the attack.
Additional information:According to DeFiLlama, the cumulative losses from various types of encrypted attacks since June have risen to approximately $6.03 million. During the same period, Humanity Protocol lost approximately US$ 32 million and Aztec Network was attacked, including 1158 ETH, 150,000 DAI and 0.4696 renBTC.
