Zero amount can also trigger minting, this authorization check is a bit over the top, the contract audit needs to be more thorough.

View Original
WuSaidBlockchainW
SlowMist Security Team issued an alert stating that LittleBoyPlus was attacked through a vulnerability, resulting in a loss of approximately 377,642 USDT, equivalent to about 610.555 BNB. SlowMist stated that the root cause of the vulnerability lies in the update function of the LBPHashrate contract, which can be triggered by a zero-amount transferFrom call and bypasses OpenZeppelin's authorization check. The attacker can directly mint LBP tokens to the PancakePair address without trading pair authorization, causing an imbalance between the balance and reserves, and then withdraw USDT through PancakePair.swap.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned