Scan to download
BTC $64,030.48 -2.33%
ETH $1,733.98 -3.03%
BNB $588.97 -2.88%
XRP $1.17 -3.29%
SOL $71.26 -2.77%
TRX $0.3201 +0.67%
DOGE $0.0845 -2.67%
ADA $0.1653 -3.37%
BCH $207.87 -2.96%
LINK $7.97 -4.13%
HYPE $71.13 -3.03%
AAVE $73.59 -3.23%
SUI $0.7479 -6.61%
XLM $0.2321 +4.26%
ZEC $463.77 -9.17%
BTC $64,030.48 -2.33%
ETH $1,733.98 -3.03%
BNB $588.97 -2.88%
XRP $1.17 -3.29%
SOL $71.26 -2.77%
TRX $0.3201 +0.67%
DOGE $0.0845 -2.67%
ADA $0.1653 -3.37%
BCH $207.87 -2.96%
LINK $7.97 -4.13%
HYPE $71.13 -3.03%
AAVE $73.59 -3.23%
SUI $0.7479 -6.61%
XLM $0.2321 +4.26%
ZEC $463.77 -9.17%

Slow Fog: Little Boy Plus was attacked, resulting in a loss of approximately $378,000

2026-06-18 10:11:55
Collection

According to Slow Fog monitoring, Little Boy Plus was attacked, resulting in a loss of approximately 377,642 USDT (about 610.555 BNB). The vulnerability was due to the _update function of the LBPHashrate contract being triggered by a zero-value transferFrom call, bypassing OpenZeppelin's authorization checks. The attacker could call this function without authorization, triggering _harvest and minting LBP tokens to the PancakePair address through LBP.mintReward. The minted LBP increased the pool balance but did not change the reserves, and the attacker subsequently drained USDT through PancakePair.swap.

app_icon
ChainCatcher Building the Web3 world with innovations.