SlowMist Founder Cos Questions OLPC/LABUBU Loss on BNB Chain Over Abnormally Changed Parameter

SlowMist Founder Cos Questions OLPC/LABUBU Loss on BNB Chain Over Abnormally Changed Parameter

N
News Editor
2026-06-20 14:01:03
SlowMist founder Cos said the roughly $1.1 million loss involving the OLPC/LABUBU liquidity pool on BNB Chain contains suspicious details. His analysis focused on the decimalsValue parameter, which was changed by the owner to an extremely large number about 46 days before the attack, after which ownership was renounced to the zero address.
SlowMistCosBNB ChainLABUBUOLPCUSDTWhale Movement

According to Odaily, SlowMist founder Cos published an analysis questioning the approximately $1.1 million fund loss involving the OLPC / LABUBU liquidity pool on BNB Chain. In his view, the incident described as a “theft” contains suspicious elements. He said the direct issue was the severe imbalance of the OLPC/LABUBU trading pair, while the reason for that imbalance was tied to a “vulnerability” in OLPC that was exploited.

OLPC/LABUBU Pair Became Severely Imbalanced

Cos explained that inside OLPC’s _update logic, when certain conditions are met, the contract can burn value * decimalsValue amount of OLPC. Under normal circumstances, decimalsValue should be 1. However, about 46 days before the attack, the owner changed this parameter to the extremely large value of 7326680472586200649. Several days later, the OLPC owner renounced ownership, making the owner address the zero address.

Based on Cos’s analysis, the attacker used the oversized decimalsValue setting today to trigger a Pair reserve burn. Because decimalsValue had been set far above the normal value, a small amount of OLPC could be used to obtain a large amount of LABUBU. This mechanism led to the imbalance in the OLPC/LABUBU liquidity pool and formed the basis for the subsequent outflow of funds.

Attacker Exchanged Funds for 1.115 Million USDT

Cos said the attacker ultimately exchanged funds at low cost for 1.115 million USDT. The suspicious point, in his analysis, lies in the decimalsValue setting itself: why the OLPC owner changed the value from the normal level of 1 to 7326680472586200649 about 46 days before the attack, and then renounced ownership several days later so that the owner became the zero address.

As described in the analysis, the core sequence of the incident involves the OLPC contract parameter change, the later abandonment of owner privileges, the triggering of Pair reserve burn, and the resulting imbalance of the OLPC/LABUBU pair. Cos’s criticism of the “theft” narrative focuses on the abnormal modification of decimalsValue as the key issue behind the loss.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
700

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.