SlowMist: The DTXT/USDT trading pair on BNB Chain was attacked, resulting in a loss of approximately 35k USDT

robot
Abstract generation in progress

Deep Tide TechFlow News. On June 05, SlowMist issued a security warning stating that the DTXT / USDT trading pair on BSC was attacked because the liquidity-addition detection logic could be forged. The attacker ultimately profited approximately 35,041.106 USDT.

The root cause is that DTXT determines whether an action is adding liquidity, removing liquidity, or selling by comparing the difference between USDT.balanceOf(pair) and the trading pair’s reserve amount. The attacker first transferred a very small amount of USDT directly into the trading pair, causing a large DTXT sell to be misidentified as adding liquidity—thereby bypassing the sell fee and swapFee logic. The attacker then used Deep Tide TechFlow News’ assistance with liquidity addition and removal via flash loans, forged a 1 wei USDT balance, and directly called Pair.swap to withdraw the USDT.

BNB-6.4%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned