News

NimbusPlatform Lost 278 BNB By Flash Loans Attack

According to the SlowMist security team’s intelligence, the NimbusPlatform project on the BSC chain was targeted on December 14, 2022, and the perpetrator profited by around 278 BNB.

To prepare for the attack, the attacker first conducted a transaction (0x7d2d8d) 8 days ago, swapping 20 BNB for NBU WBNB and subsequently for GNIMB tokens, and then transferred the GNIMB tokens to the Staking contract as a pledge.

Eight days later, the attack transaction (0x42f56d3) was formally initiated. First, 75,477 BNBs were lent via flash loans and converted for NBU WBNB, after which the majority of the nimbus tokens in the pool were exchanged for these NBU WBNB tokens.

Then, to extract rewards, use the Staking contract’s getReward method. The calculation of rewards is proportional to the value of rate, and the value of rate is determined by the values of NIMB and GNIMB tokens in the pool. Because NIMB tokens are determined by the number of tokens in the manipulated pool in the previous step of the flash loan. As a result of the exchange of a large number of tokens in the flash loan, it becomes higher, and the final calculated reward will be more than 4. The attacker eventually exchanged the last obtained GNIMB tokens and owned nimbus tokens into NBU WBNB tokens and then into BNB, and returned the flash loan profit.

The fundamental cause for this attack is that the calculation of rewards is based solely on the quantity of tokens in the pool, which allows flash loans to manipulate the system to collect more rewards than planned. When calculating token payouts, the SlowMist security team recommended that the security of the price source be maintained.

Attack transaction reference: https://bscscan.com/tx/0x42f56d3e86fb47e1edffa59222b33b73e7407d4b5bb05e23b83cb1771790f6c1

DISCLAIMER: The Information on this website is provided as general market commentary and does not constitute investment advice. We encourage you to do your own research before investing.

Join us to keep track of news: https://linktr.ee/coincu

Website: coincu.com

Chubbi

Coincu News

Chubbi

Recent Posts

Best New Meme Coins with 1000X Potential: BTFD Coin’s Hot BIG50 Discount As Baby Doge Coin, Dogs Takes Gaming to the Next Level

Explore the best new meme coins with 1000X potential. Learn how BTFD Coin leads with…

2 minutes ago

BlockDAG Surges Past $170M as BDAG250 Bonus End Countdown Begins – Aave Targets $400 & Solana Shines with Scalability

BlockDAG crosses $170.5M in presale success with BDAG250 bonus and Whitepaper V3 launch! Solana grows…

2 hours ago

Qubetics Presale Price Surge Approaches: The Best Coins to Invest in Right Now While Toncoin, and XRP Gain Traction

Discover why Qubetics, Toncoin, and XRP are the best coins to invest in right now.…

2 hours ago

Book of Meme Old News? This Best Meme Coin to Invest in 2024 Is Multiplying Gains Like a Champ

Over the years, meme coins have evolved from inside jokes into serious investment opportunities.

3 hours ago

Time’s Ticking on BlockDAG’s 5-Tier Bonus- Few Days Left to Grab It While Cardano Whales Take Action, Aave Rallies Strong

Discover BlockDAG's five-tier bonus program's closing phases that enhance buyer holdings. Gain insights on the…

4 hours ago

Best Altcoins to Buy for 2025: Qubetics Presale Surge, Solana’s Lightning Speed, and Cardano’s Blockchain Revolution

Discover why Qubetics, Solana, and Cardano are redefining the crypto landscape. Learn about milestones, price…

4 hours ago

This website uses cookies.