SlowMist: Little Boy Plus hacked, approximately $370,000 in funds stolen
Foresight News reports, according to SlowMist's monitoring, the DeFi mining protocol Little Boy Plus on BSC has been hacked, resulting in a loss of about 370,000 US dollars (approximately 610.555 BNB). The reason was that the `LBPHashrate._update()` function (located at `0x5e3c...85fe`) was triggered by a zero-value `transferFrom` call, bypassing OpenZeppelin's authorization check. This allowed the attacker to call `LBPHashrate.transferFrom(pair, DEAD, 0)` without pair authorization, thereby triggering `_harvest(pair)`. This function directly mints LBP tokens to the PancakePair address via `LBP.mintReward(pair, reward)`. The minted LBP increased the pair's balance but did not increase its reserves, enabling the attacker to drain USDT through `PancakePair.swap()`.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
CME Group Launches Micro Futures for SUI and Sui Ecosystem DeFi
SEC Crypto Asset Rules Clarify Token Buybacks and Upgrades
Cathie Wood Brings $1.3 Billion Fund Holding SpaceX and OpenAI Onchain
Ethereum’s $2,540 Retest Becomes Key Test for the Rally
