GSS Hack
What happened
On August 24, 2023 an attacker drained about $24,883 in USDT from the liquidity of the GSS token on BNB Chain. The attack used a flash loan and PancakeSwap's skim() function across two GSS pools: the GSS/USDT pair and the GSS/GSSDAO pair. An independent analysis traces the bug to the GSS token's custom _transfer() logic, which treats transfers between the two pair addresses specially, so a single skim() between the pools removed the skimmed amount from the GSS/USDT pool twice.
The attacker then sold the extra GSS back for USDT and repaid the loan.
How it happened
- The attack contract flash-borrowed 30,000 USDT from a DODO private pool and swapped it for GSS on the PancakeSwap GSS/USDT pair.
- It transferred about 707,162 GSS straight into the GSS/USDT pair without swapping, leaving the pair holding more GSS than its recorded reserves.
- It called
skim()on the GSS/USDT pair with the GSS/GSSDAO pair as recipient. Because of GSS's_transfer()handling of pair-to-pair transfers, the GSS/USDT pair's GSS balance fell by the skimmed amount twice. - It called
sync()on the GSS/USDT pair, locking in the depleted GSS reserve, then calledskim()on the GSS/GSSDAO pair to pull the excess GSS to itself. - It sold all its GSS back into the GSS/USDT pair for USDT, repaid the 30,000 USDT flash loan and kept about 24,883 USDT.
Protocol details
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.