LpdFi on BNB Chain Loses $690K in Flash Loan Attack
LpdFi protocol drained of $690K via flash loan exploit targeting price oracle vulnerability. Attackers manipulated PancakeSwap reserves to inflate interest claims and withdraw funds.
Woofun AI reports that LpdFi on BNB Chain suffered a flash loan attack resulting in losses of approximately $690,000. The vulnerability stemmed from the Lpd.price() function fetching LPD prices directly from PancakeSwap LPD/USDC spot reserves without TWAP safeguards. Attackers borrowed USDC to manipulate reserves, inflating order interest values beyond collateral worth. They then executed claimInterest() and removeLp() functions to burn protocol LP positions and withdraw USDC. The entire LpdFi LP pool of roughly 1.68 million LP was drained, with 693,000 USDC transferred to attackers in one transaction.
Comments
No comments yet.