SlowMist warns: BSC protocol Little Boy Plus was hacked, and 377642 USDT was drained
SlowMist Alert: BSC DeFi DeFi protocol Little Boy Plus was hacked, with losses of about 377,642 USDT (about 610.555 BNB). The vulnerability is in LBPHashrate._update(), which can bypass the authorization check via a zero-value transferFrom, triggering _harvest(). Unauthorized LBPs can then be minted, and USDT in the pool can be drained via PancakePair.swap() using an imbalanced exchange rate.
MarketWhisper·06-18 03:38
