FoxMarket Exploit Results in $118,700 Loss
FoxMarket, a DeFi project on BSC, suffered a loss of $118,700 due to an exploit. The attacker manipulated the liquidity pool to mint excess tokens and claim rewards.
FoxMarket experienced a security incident involving its FoxLpBondsPool.stake() function, which incorrectly calculated the _stakeAmount due to a manipulable Pancake AMM spot quote. This manipulation occurred before a significant USDT to Fox token swap, allowing the attacker to exploit the system. By utilizing flash loans, the attacker skewed the pair reserves, leading to a mismatched ratio during the addLiquidity process.
The Treasury.lpBonds() function relied on the stale value from the manipulated reserves, resulting in the minting of excess Fox tokens. Additionally, the attacker was able to send inviter rewards to an address they controlled. These rewards were subsequently sold within the same transaction, facilitating the loss of $118,700.
The incident took place on the Binance Smart Chain (BSC), which allows for tracing of the transactions involved. The on-chain record would reflect the addresses used in the exploit, providing a trail of the actions taken by the attacker during the incident.