Cellframe Network Hack

TOTAL LOST $76K
Low Flash Loan Attacks bsc

What happened

On June 1, 2023, an attacker used flash-loaned liquidity to manipulate the reserve balances of Cellframe's old and new PancakeSwap CELL pools. A flaw in the LP migration contract failed to account for the liquidity spread between those pools, allowing repeated profitable migrations. The attacker repaid the flash loans and realized 245.52282617 BNB in profit.

Technical Root Cause

LP-migration accounting trusted contemporaneous reserve conditions across old and new CELL pools without accounting for their changing liquidity spread. An attacker could manipulate both pools' reserve ratios in the same atomic execution and repeatedly extract value through the migration calculation. The flash loans supplied temporary capital; they were not the underlying bug.

Case & protocol details

Classification Protocol Logic / Token Migration Accounting
Protocol Type Exploit/Flash Loan Attack
Affected asset / contract CELL
Smart Contract Language Solidity
Official Website cellframe.net/
Protocol Twitter/X @cellframenet

Attack Timeline

The attacker borrowed 1,000 BNB from DODO and 500,000 CELL through PancakeSwap V3. They skewed the new pool by selling borrowed CELL, then skewed the old pool by swapping BNB for OLD_CELL. After adding old-pool liquidity in a preceding transaction, they repeatedly invoked the migration path while the two pools were imbalanced, withdrew the resulting new-pool liquidity, unwound positions, and repaid the loans.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.