Bullish

LpdFi on BNB Chain Loses $690K in Flash Loan Attack

2026-08-03 14:50:33

LpdFi protocol drained of $690K via flash loan exploit targeting price oracle vulnerability. Attackers manipulated PancakeSwap reserves to inflate interest claims and withdraw funds.

Woofun AI reports that LpdFi on BNB Chain suffered a flash loan attack resulting in losses of approximately $690,000. The vulnerability stemmed from the Lpd.price() function fetching LPD prices directly from PancakeSwap LPD/USDC spot reserves without TWAP safeguards. Attackers borrowed USDC to manipulate reserves, inflating order interest values beyond collateral worth. They then executed claimInterest() and removeLp() functions to burn protocol LP positions and withdraw USDC. The entire LpdFi LP pool of roughly 1.68 million LP was drained, with 693,000 USDC transferred to attackers in one transaction.

WOOFUN AI

Impact Assessment · Quick Read

The exploit highlights critical risks in protocols relying on unguarded spot prices for valuation. By manipulating PancakeSwap reserves, attackers bypassed standard security checks, draining the entire liquidity pool. This incident underscores the necessity for TWAP mechanisms in DeFi pricing oracles to prevent similar flash loan vulnerabilities.
Generated by WOOFUN AI · For reference only, not investment advice

Comments

Me
Replying to @User
0/800

No comments yet.

Notifications

Sign in to view messages
View all messagesManage subscriptions