Blockchain security company SlowMist issued a security alert today (3/18), revealing an attack incident targeting the Four.meme project. Hackers successfully bypassed trading restrictions and stole liquidity funds through a vulnerability in the PancakeSwap smart contract mechanism. This has cast a shadow over the recently trending Binance meme layout.

Attack method analysis: Pre-purchase unlisted tokens to bypass trading restrictions.

According to SlowMist's analysis, attackers purchased a small amount of emerging tokens through the 0x7f79f6df function before the official issuance of multiple emerging tokens on the Four.meme platform (pre-listing phase). This step allowed hackers to secure a certain amount of tokens before they were officially listed on PancakeSwap, laying the groundwork for subsequent attacks.

Critical vulnerability: Depositing tokens into an uncreated trading pair address.

Attackers used the 0x7f79f6df function to send emerging tokens to an uncreated PancakeSwap trading pair address. Since the trading pair does not exist, this allowed hackers to directly create the trading pair and add liquidity without needing to transfer the emerging tokens.

This operation successfully bypassed MODE_TRANSFER_RESTRICTED, which was supposed to limit trading before the token's official launch. Through this method, attackers were able to evade the preventative measures of the Four.meme project.

Stealing liquidity: Profiting from price manipulation.

After completing the establishment of the trading pair, the attackers added liquidity at an abnormal price, enabling them to acquire more funds when the price did not meet market expectations. Ultimately, the hackers successfully stole the liquidity funds in the pool, causing losses for investors.

Security warning: Smart contract development needs to strengthen prevention mechanisms.

This incident once again highlights the risks of smart contract vulnerabilities, especially regarding the security issues of decentralized exchanges (DEX) in liquidity pool and trading pair creation mechanisms. Experts recommend that development teams should take the following measures to reduce risk:

  1. Review contract functions: Ensure special functions (like 0x7f79f6df) cannot be maliciously exploited.

  2. Enhance liquidity control mechanisms: Limit the creation conditions for trading pairs to prevent malicious early injection of tokens.

  3. Implement trading monitoring: Use AI and real-time monitoring tools to identify abnormal trading behavior.

The cryptocurrency market presents both risks and opportunities; investors should always pay attention to project security to avoid unnecessary losses.

(BNB Chain opens AI meme battlefield! Shell Launchpad goes live, BSC trading volume surpasses Solana)

This article discusses the draining of liquidity from meme coins! Hackers exploited a PancakeSwap vulnerability to steal liquidity funds from the emerging meme coin Four.meme, first reported by Chain News ABMedia.