Skip to content

Latest commit

 

History

History
59 lines (24 loc) · 1.52 KB

Carson-Flash-Loan-Attack.md

File metadata and controls

59 lines (24 loc) · 1.52 KB

Carson

Carson

  • Amount Lost: $144,000.00
  • Funds Returned: $0.00
  • Category: Token
  • Date: 2023-7-26

Quick Summary

Carson ERC20 Token Suffers Flash Loan Attack Resulting in Loss of $144,000 Worth 600 BNB.

Details of the Exploit

On July 26th, 2023, Carson, an ERC20 token trading on UniSwap, was attacked through a flash loan exploit. The attacker targeted the UniSwap pool, stealing funds that were subsequently swapped for WBNB and then deposited into TornadoCash. A total loss of $144,000, equivalent to 600 BNB, was incurred. The attacker's funding was traced back to Binance's Hot Wallet.

Block Data Reference

Attacker address:

https://bscscan.com/address/0x25bcbbb92c2ae9d0c6f4db814e46fd5c632e2bd3

Malicious transactions:

https://bscscan.com/tx/0x37d921a6bb0ecdd8f1ec918d795f9c354727a3ff6b0dba98a512fceb9662a3ac

https://bscscan.com/tx/0xed52a42b2f45e4dea8d07f70d645931e4f6da65e9ab281cd3dbb9d9d21febb45

https://bscscan.com/tx/0xcd781fec34b46f8c7372a9fcc7604c210b40442dc4f1a5c274fc3f9283df39ce

https://bscscan.com/tx/0x6a94a644856c3aa1db8249b700956379b6b3a18de9b8811566fbd56c89240a01

Malicious contract:

https://bscscan.com/address/0x9cffc95e742d22c1446a3d22e656bb23835a38ac

TornadoCash Deposit Transaction:

https://bscscan.com/tx/0xe27d73643df3bea516548ff78d0ccb559f9affbe1ad844d1c10ee706e70dbc52

Proof Links: