Foresight News reports that Yucan, the founder of Slow Fog, has analyzed the recent $1.1 million loss in the OLPC/LABUBU liquidity pool on the BNB Chain and finds it suspicious. The theft occurred due to a severe imbalance in the OLPC/LABUBU trading pair. The root cause of this imbalance is a 'vulnerability' in OLPC that was exploited. When certain conditions in _update are met, it allows for burning a value * decimalsValue amount of OLPC. Normally, decimalsValue is set to 1, but about 46 days before the attack, the owner changed it to an extremely large value of 7326680472586200649. A few days later, the OLPC owner discarded ownership permissions, sending them to the 0 address.

Today, the attacker leveraged the decimalsValue's massive figure to trigger the Pair reserve burn, allowing small OLPC holders to scoop up a ton of LABUBU. In the end, the attacker low-cost swapped out 1.115 million USDT, raising eyebrows about the decimalsValue configuration. Why would the OLPC owner set such a high value?