DailyNews
vip

Jinse Finance reported that according to the Beosin EagleEye security risk monitoring, early warning and blocking platform monitoring of the blockchain security audit company Beosin, on May 24, 2023, the CS (CS) token project on the bsc chain was attacked. The reason is that the sellAmount in the transfer function of the token is not updated in time. The Beosin security team will briefly analyze and share as follows:


1. The attacker uses the flash loan to borrow BSC-USD and convert it into CS tokens.
2. The attacker starts to sell 3000 CS tokens, and this step will set sellAmount.
3. The attacker will trigger sync() by transferring money to himself. In this function, the sellAmount of the previous step is used and this function will destroy the CS tokens in the pair. After Sync, sellAmount will be set to 0. Repeat steps 2 and 3 to continuously reduce the number of CS tokens in the pair, and increase the price of CS tokens, so that more BSC-USD can be exchanged in the next step.
Borrow 80,000,000 BSC-USD, exchange for 80,954,000 BSC-USD, repay 80,240,000 BSC-USD, and make a profit of about 714,000 BSC-USD.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Share
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)