PublicAML

MCN Labs LPBonus contract exploited for $92,600 loss

MCN Labs experienced a loss of approximately $92,600 due to an exploit in their LPBonus contract. The attacker manipulated reserve values during reward accounting to claim excessive rewards.

The incident involved the LPBonus contract associated with MCN Labs, where an attacker exploited inconsistencies in the reward accounting process. The contract used different MSN reserve values for accrual and withdrawal, which created an opportunity for manipulation. The attacker first reduced the reserve to approximately 89.33 MSN during the accrual phase and subsequently increased it to around 491.11 MSN before executing the UserRemoveLp function. This allowed a newly registered liquidity provider to claim about 1,442,165.71 FIST tokens against only 940,041.61 FIST of available reward funding.

The total loss incurred from this exploit amounted to approximately $92,600. The incident highlights a flaw in the reward distribution mechanism of the LPBonus contract, which was susceptible to manipulation through reserve value adjustments. The exploit's impact was significant, resulting in a substantial financial loss for MCN Labs.

This incident occurred on the Binance Smart Chain (BSC), which means that the transaction details and the addresses involved can be traced on this blockchain. The manipulation of reserve values and the subsequent claim of rewards can be analyzed through the on-chain records, providing insights into the exploit's execution and the flow of funds.

Addresses in this incident

Roles are attributed to the source that stated them. Addresses without an attributed role are listed because coverage mentioned them, not because we assign them a part in the incident.

Sources

Share:XTelegramLinkedIn
MCN Labs LPBonus contract exploited for $92,600 loss | PublicAML