On December 10, 2024, the Labubu Token on the Binance Smart Chain (BSC) was exploited due to a flaw in its transfer logic. The vulnerability allowed an attacker to manipulate the token's balance system and increase his own balance without properly transferring the token.
Attacker’s address: 0x27441c62dbe261FDF5e1feec7eD19cF6820D583b
Attacker’s contract addresses: 0x2Ff0Cc, 0x5CB78b
Vulnerable contract: 0x2fF960F1D9AF1A6368c2866f79080C1E0B253997
Attack transaction: 0xb06df37
Upon execution, the sender's balance decreased by the transferred amount and the recipient's balance increased by the same amount due to the incorrect logic.
The attacker then swapped these siphoned LABUBU tokens for 12,608,287,525 VOVO tokens on PancakeSwap.
Following this, the attacker exchanged the VOVO tokens for 17 BNB, successfully laundering the stolen funds.
The root cause lay in the transfer function's failure to prevent the same address from being used as both the sender and receiver, allowing an unintended balance inflation.
Dive into the funds flow here:
Choosing a reputable smart contract audit firm like QuillAudits ensures that your protocol undergoes rigorous scrutiny from experienced security professionals. QuillAudits specializes in uncovering critical vulnerabilities and providing actionable remediation strategies. Our expertise helps safeguard your project from attacks, ensuring that security issues are addressed proactively.
Join 1000+ leaders who secured themselves from losing Billion Dollars.
Get Pure Alpha Straight to Your Inbox. Miss this, and you’re missing out.
Insider Secrets - Delivered Right to You. Subscribe now.