EAC Hack

Reported loss $6K
BNB Chain
Spot Price Manipulation

What happened

On August 29, 2023, an attacker made 6,376.85 BSC-USD from the EAC token on BNB Chain. EAC's fund contract exposed a function with no permission check. The function spent the contract's own BSC-USD to buy EAC on PancakeSwap. The attacker used a flash loan to buy EAC first, called that function to push the price up with the project's money, and then sold.

According to Lunaray's analysis, the EAC team later upgraded the proxy to a new logic contract (0x2deb06785a9392c9f7fdc959d429bb0f5774610f) that adds the missing permission check.

How it happened

  1. The attack contract 0x20dcf125f0563417d257b98a116c3fea4f0b2db2 flash-borrowed 300,000 BSC-USD from a DODO pool.
  2. It swapped the loan for EAC on the PancakeSwap V2 pair and received 2,320.81 EAC after EAC's 3% buy fee.
  3. It called the EAC fund proxy 0xa08a40e0...63561 (selector 0xe6a24c3f) and passed the contract's own 14,300 BSC-USD balance. That swapped the protocol's funds into EAC, lifting the pool price from about 125 to about 407 BSC-USD per EAC.
  4. It sold its EAC back into the pair (about 2,251 EAC after sell fee, burn and the minimum-hold rule) for 306,376.85 BSC-USD, repaid the 300,000 loan and kept 6,376.85 BSC-USD. Attack tx: 0x477f9ee698ac8ae800ffa012ab52fd8de39b58996245c5e39a4233c1ae5f1baa. Attacker EOA: 0x27e981348c2d1f5b2227c182a9d0ed46eed84946.

Protocol details

Classification Oracle Manipulation
Protocol Type Token
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.