PublicAML

ORBToken Exploited for $32,610.72 on BSC

ORBToken suffered an exploit resulting in a loss of $32,610.72. The attack involved exploiting vulnerabilities in the token's functions and mechanisms.

Attackers exploited vulnerabilities in ORBToken’s receive() function, which automatically granted maximum allowance, and ORBCore’s whitelist tax exemption. This allowed the attackers to utilize the addPoolAndSell function, which lacked a reentrancy guard, enabling them to perform repeated tax-free sells. The combination of these factors facilitated the extraction of funds from the protocol.

Additionally, the attackers took advantage of the burnLP function, which destroyed large amounts of ORB tokens in the liquidity pool. Following this, a sync() operation was executed to manipulate the reserves, further aiding in the extraction of funds. The total loss amounted to approximately $32,610.72.

The incident occurred on the Binance Smart Chain (BSC), which allows for tracking of transactions and movements of the affected tokens. The on-chain record reflects the actions taken by the attackers, including the manipulation of the liquidity pool and the subsequent extraction of funds.

Sources

Share:XTelegramLinkedIn
ORBToken Exploited for $32,610.72 on BSC | PublicAML