CryptoWorld News reports that the SlowMist Security Team has issued an alert stating that littleboyplus has suffered a vulnerability attack, resulting in a loss of approximately 377,642 USDT, equivalent to about 610.555 BNB. SlowMist stated that the root cause of the vulnerability lies in the update function of the lbphashrate contract, which can be triggered by a zero-amount transferFrom call, bypassing OpenZeppelin's authorization check. The attacker can mint LBP tokens directly to the PancakePair address without trading pair authorization, causing an imbalance between balances and reserves, and then withdraw USDT through PancakePair.swap.
CoinNetwork
