According to LaunchZone, an attacker used an exploit to steal $700,000, a decentralized finance (DeFi) protocol built on the BNB Chain.
$700,000 drained from BNB Chain-based DeFi protocol LaunchZone
Even though over 80% of the LaunchZone liquidity pool was depleted on February 27th, details are still sketchy. Telegram users were urged not to invest in the project's token sale until additional details were released.
According to statistics from various blockchain explorers, the value of its native currency LaunchZone (LZ) fell by over 80% as funds were switched out using PancakeSwap.

After reviewing the data, an analyst from Verichains concluded that the breach occurred because of an unauthenticated security hole in a contract labeled as Contract X (currently located at the address 0x6d8981847eb3cc2234179d0f0e72f6b6b242a01).
Keep in mind that over a year ago, a sizable quantity of LZ and BUSD was "authorized" by the "LZ Deployer" wallet and sent to this contract.
Analysis of the Flow of an Attack
On February 27th, 2023, at 14:32 local time in Vietnam, an IP address identified as DND Exploiter compromised LZ Token.
-
The deal led to a precipitous drop in the price of LZ Token: https://bscscan.com/tx/0xaee8ef10ac816834cd7026ec34f35bdde568191fe2fa67724fcf2739e48c3cae
-
With the help of an "attack contract," the hacker was able to carry out the following LZ Token attack flow:
Invoke a procedure that uses Biswap to effect a trade from LZ to BUSD (called the swap function). More than a year ago, the "LZ Deployer" wallet authorized 1 billion LZ, or 39 million BUSD, for this function as part of Contract X.
The contract for 1 billion LZ is approved by LZ Deployer. https://bscscan.com/tx/0x3ab13a622105fdcf0293ed1a0a7918375e1a05123160efdc5e23ec121ac6d944
The deal was approved by LZ Deployer and is worth more than $39,000,000 USD.
https://bscscan.com/tx/0x444edcefe7de6504ae70deb292c80211dbff0ddb13bf6689cb05d5a068307ca0
-
The intruder used a third-party contract's swap function to exchange 9.8 trillion LZ, with the BSW-LP Pair returning roughly 7 BUSD to LZ Deployer (Biswap).
-
The hacker then deposited 50 BUSD into the attack contract and swapped it for almost 9.8 trillion LZ via Biswap.
-
At last, the hacker used PancakeSwap to trade more than 9.8 trillion LZ for roughly 88k BUSD. Currently, the value of an LZ Token has fallen by a factor of 46.
-
The hacker took roughly $88k worth of BUSD, transferred it to their own wallet, and then activated a self-destruct attack contract.
Some related addresses:
- LZ Deployer: 0xdad254728A37D1E80C21AFae688C64d0383cc307
- Attacker: 0x7d192FA3a48C307100C3E663050291Fff786aA1F
- Attack Contract: 0x1C2B102f22c08694EEe5B1f45E7973b6EACA3e92
- Contract X: 0x6D8981847Eb3cc2234179d0F0e72F6b6b2421a01
- BSW-LP: 0xDb821BB482cfDae5D3B1A48EeaD8d2F74678D593
Vulnerability and cause analysis
The above shows the hacker's actions while making roughly 88k BUSD off of the dump of LZ Token. This section provides an in-depth examination of the attack's vectors and points of entry.
As for the implementation contract of SwapX Proxy, we have settled on Contract X (not yet validated and audited), to which users will be able to transmit data and make calls. https://bscscan.com/address/0x0ccee62efec983f3ec4bad3247153009fb483551
The BSCex ecosystem is connected to SwapX, an AMM, and LZ Token is a part of this ecosystem.
Security flaws in the contract's bytecode include the following.
-
As an alternative to "delegatecall," the "call" keyword is used in this version of "call."
-
With the implementation's functions, each proxy can make unlimited calls to the outside world.
-
In particular, the function that was responsible for the swap functionality in the implementation introduced a critical flaw because it allowed "transferfrom()" to be called from any address, rather than the more secure "msg.sender" in other swaps. Because of this, a hacker can "assist" another person swap by manipulating the data call that is being passed in.
The hacker exchanged a large number of LZ tokens for BUSD via the Biswap pair, causing a precipitous drop in the price of LZ. This was compounded by the "LZ Deployer" wallet, which had previously used SwapX and approved a large number of BUSD and LZ tokens (possibly due to carelessness when using SwapX's front-end when swapping). The hacker spent 50 BUSD to repurchase 9.8 million LZ tokens, and subsequently sold those tokens on the trading platform PancakeSwap for roughly $88,000 USD.
Source: Verichains
If you aspire to become a pro-crypto trader, then you have clicked at the right place. CoinScreener.ai advanced technical analysis and AI-generated signals, rich data sources from more than 1000 Future & Spot markets enriched by Machine Learning, and major cryptocurrency exchanges in the world to screen for market trading signals, monitor and analyze the trading behavior of Whales, Top Traders to identify the best market trends in real-time and make the most profit from your trade today.
Follow CoinScreener: https://linktr.ee/coinscreener.ai
#coinscreener #coin #screener #coinscreener.ai #crypto #ai #cryptosignals #cryptocoin #token #cryptoscreener #screenerapp #screenertool #tradingsignals #aitradingsignals #technicalanalysisscreener #technicalanalysis #tradingbot #cryptohopper #cryptobot #dcabot #robot #calculatorcrypto #btc #binance #liquidations #fundingrate #cryptoscreener #btcliquidation #cryptoliquidation #Liquidation #future #futuretrading #cryptocalculator #costbasic #fed #FOCM #Federalreserve #CEX #DEX #KYC #RSI #indicator #P2P #gridtrading #perpetualcontracts #perpetualfutures #slippage #offchain #onchain #halving #bulltrap #beartrap #Bidask #spread #phishing



