BNB Chain exploited in flash mortgage assault, attacker snags $1.27M

A flash mortgage assault on the BNB Chain has resulted within the largest single arbitrage revenue in its historical past, based on safety specialists.
The attacker exploited a value manipulation vulnerability on the BH token (BH) and made off with $1.27 million in USDT.
As reported by Chinese language journalist Colin Wu on Oct. 11, the attacker used a bot to borrow a considerable amount of USDT from a lending platform after which manipulated the value of BH on PancakeSwap, a decentralized change on the BNB Chain.
The bot then swapped USDT for BH at a low value and eliminated liquidity from the BH/USDT pair at a excessive value, incomes a large revenue within the course of. The bot spent solely $4.16 in charges for the assault and transferred all of the earnings to the crypto mixing service Twister Money.
Beosin, a blockchain safety firm, defined the small print of the assault on X. They stated the attacker exploited a perform within the BH contract that allowed them so as to add USDT to the contract with out affecting the liquidity ratio.
The contract assumed the liquidity ratio was about 1 USDT:100 BH. Nevertheless, the attacker modified it to 1 USDT:2 BH by swapping USDT for BH via PancakeSwap. This fashion, the attacker may withdraw extra USDT than they deposited.
Beosin warned that this was a premeditated assault on the BH token. Furthermore, PeckShield, one other blockchain safety agency, confirmed on X that the handle concerned within the assault initially acquired funds from Twister Money.
In a flash mortgage assault, the attacker rapidly borrows a big sum of an asset with no collateral from a DeFi lending platform, makes use of it to control vulnerabilities in different protocols, and repays the mortgage throughout the identical transaction, usually leading to vital earnings on the expense of the focused protocols.
