Cellframe Network Hack
What happened
On June 1, 2023, an attacker used flash-loaned liquidity to manipulate the reserve balances of Cellframe's old and new PancakeSwap CELL pools. A flaw in the LP migration contract failed to account for the liquidity spread between those pools, allowing repeated profitable migrations. The attacker repaid the flash loans and realized 245.52282617 BNB in profit.
LP-migration accounting trusted contemporaneous reserve conditions across old and new CELL pools without accounting for their changing liquidity spread. An attacker could manipulate both pools' reserve ratios in the same atomic execution and repeatedly extract value through the migration calculation. The flash loans supplied temporary capital; they were not the underlying bug.
Case & protocol details
Attack Timeline
The attacker borrowed 1,000 BNB from DODO and 500,000 CELL through PancakeSwap V3. They skewed the new pool by selling borrowed CELL, then skewed the old pool by swapping BNB for OLD_CELL. After adding old-pool liquidity in a preceding transaction, they repeatedly invoked the migration path while the two pools were imbalanced, withdrew the resulting new-pool liquidity, unwound positions, and repaid the loans.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report twitter.com
- report Report twitter.com
- analysis Cellframe official June 2023 AMA cellframe.net
- analysis SlowMist: Cellframe Hack Analysis slowmist.medium.com
- analysis BscScan attacker address bscscan.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.