Headline: CCC token on BNB Smart Chain hit by sell() exploit — attacker burns LP tokens, drains ~$117K A BNB Smart Chain (BSC) token called CCC suffered a contract-level exploit on Aug. 28 that resulted in an estimated $117,000 loss after an attacker manipulated the token’s sell() function and burned CCC tokens held in the liquidity pool. What happened - Blockchain security firm TenArmorAlert flagged suspicious activity and traced the incident to the CCC contract’s sell() function. Their monitoring detected that the function was used to burn CCC tokens directly from the liquidity provider (LP) pair, which coincided with abnormal price movement for the token. - TenArmorAlert estimated total losses at roughly $117,000 and cited an attack transaction that begins with 0x89d805064, but the firm did not publish a full breakdown of assets removed or the attacker’s final proceeds. - At the time of the alert, it was not clear how the attacker gained the ability to trigger the affected sell() function — whether through a permissions bypass, an external contract interaction, or an overlooked access control. TenArmorAlert’s initial post did not name the decentralized exchange hosting the LP pair, nor did it report any pause, recovery actions, or compensation from the CCC team. Why this matters Burning tokens out of the LP pair can change the balances that automated market makers use to price trades, producing sudden price swings and disadvantaging liquidity providers. TenArmor linked the token burn to the abnormal CCC price movement, and independent outlets repeated the same $117K figure and sell() function explanation. Context — similar attacks on BNB Chain this year This incident echoes several earlier exploits where contract functions were manipulated to drain value from liquidity infrastructure on BNB Chain: - Swan Treasury (July): ~$625K lost after an off-chain signer key was used to forge buy() signatures, allowing attackers to buy STY at a deep discount before selling into the STY–USDT pool. - Balance Coin / 42DAO (July): An estimated $915K incident where unbacked BLC tokens were minted and swapped on PancakeSwap V2, crashing BLC from near $1 to a fraction of a cent. - Token of Power (June): ~$1.58M drained from a TOP/WETH Balancer V1 pool following what firms described as a governance-takeover style exploit. - DxSale (May): Allegations of a hidden backdoor that allowed withdrawal of BNB locked by 1,400+ liquidity providers, with losses estimated at $7.3M. - SafeMoon (March 2023): A public burn function vulnerability allowed tokens belonging to other addresses (including LP tokens) to be burned, costing the protocol about $8.9M. Takeaway The CCC incident reinforces recurring risks around token contract functions that can affect liquidity pool balances. Until a detailed post-mortem or mitigation plan is published, liquidity providers and token teams should review access controls, restrict risky public functions, and prioritize third‑party audits. No further technical breakdown, recovery actions, or information about the attacker had been disclosed by TenArmorAlert at the time of their alert. Read more AI-generated news on: undefined/news
