A long-inactive PancakeSwap liquidity provider lost about $2.96 million after signing a malicious EIP-7702 approval, according to monitoring by Specter. The attacker removed roughly $1.48 million in BSC-USD liquidity and another $1.48 million in BUSD liquidity that had been supplied by the victim. Specter said the attacker then swapped the BUSD portion into ETH. Of the stolen funds, about $1.46 million has already been deposited into Tornado Cash, while around $1.48 million in USDT remains in the attacker-controlled address. The incident centers on a malicious authorization and involved assets previously deployed on PancakeSwap as liquidity.
According to Specter, a long-inactive PancakeSwap liquidity provider (LP) lost about $2.96 million after signing a malicious EIP-7702 approval.
The attacker removed roughly $1.48 million in BSC-USD liquidity and another $1.48 million in BUSD liquidity that had been provided by the victim, then swapped the BUSD into ETH.
Specter said about $1.46 million has already been deposited into Tornado Cash, while the remaining roughly $1.48 million in USDT is still held in the attacker address.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.