SlowMist Warning: BSC Protocol Little Boy Plus Hacked, $370k Looted

BSC On-Chain DeFi Mining Protocol Little Boy Plus Hacked, Loss Approximately $370k (about 610.5 BNB).
SlowMist Monitoring Indicates the Vulnerability Originates from the LBPHashrate._update() Function Being Bypassed by Zero-Value transferFrom Authorization Checks, Allowing Attackers to Drain All USDT via PancakeSwap Liquidity Pool.
(Background Recap: BSC Official: 8 Flash Loan Attacks Possibly Caused by the "Same Hacker Group"!)
(Additional Context: Privacy Coin Aztec Smart Contract Hacked, $2.19 Million Stolen! SlowMist Reveals "Settlement Bypass" Vulnerability)

Blockchain Security Firm SlowMist Monitored that on June 18, the BSC DeFi mining protocol Little Boy Plus was hacked, resulting in a loss of about $370k (approximately 610.5 BNB). SlowMist pointed out that the core vulnerability lies in the LBPHashrate._update() function.

Zero-Value Transfer Bypasses Authorization Checks

SlowMist analysis indicates that the vulnerable function is located at address 0x5e3c…85fe, and the issue is that this function can be triggered by a zero-value transferFrom call, bypassing OpenZeppelin's allowance check mechanism. Specifically, an attacker can call LBPHashrate.transferFrom(pair, DEAD, 0) directly without obtaining permission for the trading pair, which then internally calls _harvest(pair).

LBP Token Minting Causes Liquidity Imbalance

The _harvest(pair) function subsequently mints LBP tokens directly into the PancakeSwap liquidity pool address via LBP.mintReward(pair, reward). This artificially created LBP increases the apparent balance of the trading pair but does not update the actual reserves, leading to a price imbalance within the liquidity pool. Exploiting this vulnerability, the attacker uses PancakePair.swap() to drain all USDT from the pool.

🚨SlowMist TI Alert🚨

💸 @LittleBoyPlus has been exploited. Loss: ~377,642 USDT (~610.555 BNB)

🔍 Root Cause: The LBPHashrate._update() function (at 0x5e3c…85fe) is triggered by zero-value transferFrom calls, which bypasses OpenZeppelin's allowance check. This allows an…

— SlowMist (@SlowMist_Team) June 18, 2026

BNB-2.52%
CAKE-1.16%
AZTEC-7.51%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned