Loading...
**[BSC Unverified Contract Hit by Flash Loan Attack, Losses Approx. $150,000]** BlockSec Phalcon alerts indicate that a suspicious transaction occurred on Binance Smart Chain (BSC) several hours ago, targeting an unverified contract (address: 0x93fD192e1CD288F1f5eE0A019429B015016061F9), resulting in a loss of approximately $150,000. The attack exploited a vulnerability in the contract's referral reward mechanism, where the reward calculation relied on the manipulatable spot price of the BURN/BUSD trading pair. The attacker manipulated the BURN price through a flash loan and repeatedly created new contracts to bypass the "one referral per address" and maximum investment limit restrictions, thereby accumulating inflated BUSD referral rewards. Subsequently, they sold the borrowed BURN tokens, causing the price to drop, and profited by purchasing BURN at the lower price. This incident highlights the potential risks of price-dependent mechanisms in smart contract design.