Crypto pool liquidity is the total assets locked in a decentralized finance (DeFi) liquidity pool.
Hackers manipulate pool liquidity to create artificial imbalances that allow them to control prices and execute profitable trades.
Furthermore, it often results in significant financial gains at the expense of other users in the ecosystem.
Cybersecurity researchers at Check Point recently reported that their threat intelligence system reported pool manipulation, resulting in a 22,000% token increase.
During this manipulation, the attacker managed to steal $80,000 by exploiting the liquidity pool.
Hackers are exploiting crypto liquidity pools
During the analysis, researchers found two wallets created by the scammer, which we mention below:
- 0x48F7661E84A823505d683D092a2DccdA1e5aA119
- 0x151a2498826F9fe6f214C92bB1811f7d1153b630
Wallet One used the WIZ token (0x2ae38b2b47bf41ba4ab8f749b092fdd02b00bc1e) and its liquidity pool (0x6e0367d897a8fd8bcbc44b4e2a14bafa904360aa) with WETH and WIZ reserves.
Wallet two (0x151a2498826F9fe6f214C92bB1811f7d1153b630) created a malicious contract (0x796042E0032aC5247bc04A49102d49c5b5A5cF0c) and exploited a backdoor to manipulate the WIZ token price, resulting in theft of $80,000.
Below we have listed all the operating methods:
- Token creation
- Token advertising
- Investor participation
- Pool Manipulation
- The cheater's profit
Attack Flow (Source – Control Point)
Imagine a digital reservoir containing Token A and Ethereum. Users exchange these tokens freely, which affects their values. The scammer manipulates the pool by destroying Token A and increasing its value through supply and demand dynamics.
The reduction of Token A increases the value of Ethereum and causes a significant increase in the price of the token, especially for WIZ in the WIZ/WETH pool.
This strategy temporarily increases token prices in liquidity pools by burning one side. Decentralized exchanges based on pool ratios are vulnerable to exploitations such as “rug pulls”.
To achieve the _burn function, the scammer bypasses checks by setting limitsEnabled to False, which is achieved by running “removeLimits”.
The second check requires the From address to return False for ExcludeFromFees and True for isExcludedForMaxTxAmount. Performing public functions with the scammer's contract address as input will verify these conditions.
Checkmark (source – checkpoint)
When examining the WIZ token, experts find a backdoor where the scammer, who is likely the creator, set the ExcludedForMaxTxAmount to True for the malicious contract address.
This link points to the same person who designed both the WIZ token and the scam.
The scammer temporarily inflates token prices in the liquidity pool and manipulates balances to influence decentralized exchange rates. This tactic exposes the vulnerability of liquidity pools tied to various contracts.
By exploiting backdoors, fraudsters manipulate liquidity pools, highlighting the need to be vigilant against fraudulent schemes in decentralized finance.
Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers
Comments are closed.