🚨 EXPLOIT ALERT: CashCowCoin Drained for ~$117K

Another day, another rug. Attacker exploited a trash unverified router implementation on BSC.

How it went down:
• Router's sell() function was fundamentally broken
• After swapping $CCC → $WBNB on PancakeSwap, the proxy called a privileged token function that yeeted ALL post-tax $CCC from the Pair straight to dead address
• Then called Pair.sync() — burning sell-side $CCC while keeping reduced $WBNB reserves
• Attacker looped this 80 times, draining reserves dry

Key addresses:
🔴 Attacker EOA: 0x7977bdeee3a79dc85cc18739692e796b5d2513c4
🔴 Attack Contract: 0x7738b4d7c25e9a7092ae1ab402343b20340daeaf
🔴 Exploited Proxy: 0xf523224c6171f81c54b93f474ed4c78de91241c7
🔴 Vulnerable Implementation: 0x4287742e50fad6d3351000fd31632412ab29a9ac
🔴 Victim Pair (CCC/WBNB): 0x1dbe9458a6840784d5defd62c6b71386100097c0
🔴 Profit Splitter (holds funds): 0xbabf70e515ae71a2177e624994a68d10c61d7a9f

Lesson: Unverified contracts = exit liquidity. DYOR or get rekt.

via @SlowMist_Team