The SafeMoon token liquidity pool lost $8.9 million after a hacker exploited a newly created “Burn” smart contract feature that artificially inflated the price and allowed actors to purchase SafeMoon at a much higher price for sale.
Liquidity pools on DeFi platforms are large deposits of money (cryptocurrency) that facilitate trading, provide market liquidity, and generally allow exchanges to function without third-party borrowing.
SafeMoon confirmed the security incident on Twitter today and stated that it is currently working to resolve the issue.
SafeMoon CEO John Karony stated that the attack took place on Tuesday, March 28 and affected the platform’s SFM:BNB liquidity pool but not its exchange.
“We have located the suspected exploit, patched the vulnerability and are engaging a chain forensic consultant to determine the precise nature and scope of the exploit,” Karony’s statement said.
“Users should be assured that their tokens remain secure. I would like to assure you that the other LP pools on the DEX will not be affected, nor will any of our upcoming upgrades and releases.”
Exploit Details
Blockchain security researchers PeckShield have shared more details about the vulnerability that the hacker exploited to conduct the $9 million SafeMoon heist.
According to PeckShield, a recent update introduced SafeMoon’s new smart contract feature that burns tokens. Unfortunately, the feature was mistakenly set to public with no restrictions, allowing anyone to run it as they please.
Karony previously explained that this system would only be used for emergencies, such as when the liquidity pool was at risk from malicious smart contracts, excessive slippage, and other temporary losses.
The hacker used the feature to burn large amounts of SafeMoon tokens, causing the token’s price to skyrocket.
Error highlighted by PeckShield
As soon as the price rose, another entity sold SafeMoon at the manipulated price, withdrawing $8.9 million from the SafeMoon:WBNB liquidity pool.
A few hours after the attack, the actor who turned SafeMoon into BNB claimed that he was not the original hacker but “accidentally front-run” after the price artificially inflated due to the burn() function exploit had been driven.
Although it is not clear if the owner of this wallet is the same person who exploited the bug, they offer to return the stolen funds to SafeMoon.
“Hey relax, we accidentally launched an attack against you, we want to return the money, set up a secure communication channel, let’s talk,” said a comment added to the transaction.
Since then, the person has transferred 4,000 Binance Coins (BNB) worth $1,264,440.00 to a different address, making the front run look less random.
Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers
Comments are closed.