CS Hack
What happened
CS token's pool was exploited via a flash loan attack. The attacker used 80,000,000 $USD to manipulate the token price and made a profit of 714,285 $USD.
CS is a BEP20 token trading on PancakeSwap. The token's CS/USD pool was drained via a flash loan attack. The attack started from the malicious contract deployment by the exploiter, which took 80,000,000 $USD as a flash loan from the BSC-USD pool.
Consequently, multiple swaps with a small amount of 5,000 $USD was continuously repeated to manipulate the pool's price. After reaching some conditions, the attacker could swap the $CS tokens back with an unfairly high price and the total amount gained back went to 80,954,285 $USD. 240,000 $USD were paid back to the BSC-USD pool as a flash loan fee after the base amount was returned.
The exploiter's profit reached 714,285 $USD, which was transferred to the initial EOA, and then distributed between several addresses. All the malicious actions were performed in a single transaction.
Attacker address:
https://bscscan.com/address/0x2cdeee96…4027ba
Malicious transaction:
https://bscscan.com/tx/0x906394b2…87baa4
Malicious contract:
https://bscscan.com/address/0x90fa57d2…6ee2e3
Case & protocol details
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report twitter.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.