Headline: CCC token on BNB Chain exploited — attacker burns LP tokens, drains ~$117K A smart-contract exploit on the CCC token on BNB Smart Chain (BSC) resulted in an estimated $117,000 loss after an attacker manipulated the token’s sell() function to burn CCC tokens held in its liquidity pool, blockchain security firm TenArmorAlert reported. What happened - TenArmorAlert’s monitoring systems flagged suspicious activity on Aug. 28 and traced the incident to CCC’s sell() function. According to the alert, the function was used to burn CCC tokens directly from the liquidity provider (LP) pair, which caused abnormal price movements. - The security firm estimated the total loss at roughly $117,000 and pointed to an attack transaction beginning with 0x89d805064, but did not publish a full breakdown of assets removed or the attacker’s final proceeds. - Crucially, TenArmorAlert did not disclose how the attacker obtained the ability to trigger the vulnerable function — whether via bypassed access controls, a permission flaw, or a chained interaction with another contract remains unclear. Why this matters - Burning tokens from an LP pair changes the token balances the automated market maker relies on, which can skew prices and enable value extraction without a direct withdrawal. TenArmorAlert linked the burn to the observed abnormal price action, though a complete technical sequence has not been released. - At the time of reporting there was no public information on whether the CCC team paused the contract, adjusted permissions, recovered funds, or planned compensation for affected liquidity providers. Bigger picture — a recurring pattern on BNB Chain - The CCC incident echoes several recent attacks targeting token contract logic and liquidity infrastructure on BNB Chain: - July: Swan Treasury lost about $625,000 after an attacker used a compromised off-chain signer to exploit a buy() calculation and acquire STY tokens at a steep discount. - July: Balance Coin (BLC) collapsed after roughly $915,000 worth of activity, where attackers minted unbacked tokens and sold them on PancakeSwap V2. - June: Token of Power suffered a $1.58 million loss through an attack that drained WETH from its Balancer pool. - May: DxSale was hit for an estimated $7.3 million after an alleged backdoor enabled withdrawals of BNB locked by many liquidity providers. - March 2023: SafeMoon lost about $8.9 million when a public burn function allowed tokens from other addresses — including the LP — to be burned. What’s next - TenArmorAlert has not yet released a detailed post-mortem or recovery plan for the CCC exploit, and no further information about the attacker was available at the time of the alert. - The incident reinforces the risk profile for projects with on-chain token functions that can affect LP balances — and the importance of rigorous access controls, audits, and emergency measures (such as pausability and timelocks) for protecting liquidity providers. We’ll update this story when code-level analysis or official statements from the CCC team are published. Read more AI-generated news on: undefined/news