SlowMist
SlowMist|Aug 17, 2026 03:45
🚨SlowMist TI Alert🚨 💸 Fox Loss: 118.7k USD 🔍 Root Cause: Root Cause: FoxLpBondsPool.stake() calculated and fixed _stakeAmount from a manipulable Pancake AMM spot quote before executing its own large USDT→Fox swap. That swap materially skewed the pair reserves, so the subsequent addLiquidity() supplied Fox and USDT according to a drastically different reserve ratio, yet _stakeAmount was never recomputed from the actual assets deposited or the fair value of the resulting LP tokens. Treasury.lpBonds() blindly trusted this stale, economically unsupported accounting value, minted Fox based on it, and immediately transferred inviterRewardAmount to an attacker-controlled referral address. The attacker sold that newly minted Fox back into the pair in the same transaction. Flash-loan liquidity enabled the scale of the exploit, while the lack of manipulation-resistant pricing, accounting-to-backing validation, and delayed reward settlement constituted the core vulnerability. 📌 Attacker: 0x3a82a2a77061017927e5331fffd07c0308a1d2da (controlled by 0x5670d36f00bc7f6860b6afddb288e3668efc0ef9) 📌 Victim: 0xaab18bcdee287aea288c0560612caadf7c328803 (USDT/Fox PancakePair) 📌 Vulnerable Contracts: FoxLpBondsPool: 0x58e2a853bb14e46befd3148bd4280370fea4655a | Treasury: 0x87614d97808dcdecb069fe8489848fa1c001e04d Powered by http://SlowMist.AI Tx: https://bscscan.com/tx/0x8e1775cbfd44db29744cc6687ff1822d2c47321de6e94062f789ad6181ad5514(SlowMist)
+5
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads