On Dec-03, 2024, BYC token got exploited due to a vulnerability in the “autoBurnLiquidity” function. The hacker manipulated the “lpBurnFrequency” parameter by exchanging a large amount of USDT for BYC and transferring all BYC to the PancakeSwap pair, which inflated the parameter's value. By calling "autoBurnLiquidity," the attacker reduced the BYC reserve to 1, enabling him to drain all USDT from the liquidity pool, resulting in a $100k loss.
0x14CfA851ff34952A223Ea7fDF621a05B128411ef
0x9B227
, 0x0x8a3e
0x9A69eB74060e2808344Ac35Bb5825051B89BBE76
0x177b87b
The autoBurnLiquidity
function in the BYC contract is designed to burn tokens by transferring them from the PancakeSwap liquidity pool to the DEAD address.
lpBurnFrequency
variable.The value of lpBurnFrequency
increases when tokens are transferred to the pancake pair (for example, during exchanges of BYC for USDT).
lpBurnFrequency
threshold.Once this threshold was manipulated, the attacker exploited the functionality of autoBurnLiquidity
to drain the liquidity pool.
autoBurnLiquidity
function execution, the BYC reserve in the liquidity pool was reduced to just 1 BYC.The root cause of the exploit lies in the autoBurnLiquidity function's reliance on the lpBurnFrequency parameter, which was manipulatable through token transfers to the liquidity pool. The function failed to impose limits or validation checks on how lpBurnFrequency could be increased, allowing the attacker to inflate it artificially. Once inflated, the function burned a disproportionate amount of BYC tokens from the pool, creating an imbalance in the reserves.
See the funds flow here:
autoBurnLiquidity
only executes when specific, well-defined conditions are met, such as requiring a minimum balance or specific time intervals between burns.lpBurnFrequency
can increase to prevent malicious inflation.Choosing a reputable audit firm like QuillAudits ensures that your protocol undergoes rigorous scrutiny from experienced security professionals. QuillAudits specializes in uncovering critical vulnerabilities and providing actionable remediation strategies. Our expertise helps safeguard your project from attacks, ensuring that security issues are addressed proactively.
Join 1000+ leaders who secured themselves from losing Billion Dollars.
Get Pure Alpha Straight to Your Inbox. Miss this, and you’re missing out.
Insider Secrets - Delivered Right to You. Subscribe now.