IEXCBP Hack

Reported loss $97K
BNB Chain
Spot Price Manipulation

What happened

IEXCBP on BNB Chain was exploited for roughly $97.4K when an attacker drained 783,058 IEX from its contract and realized proceeds through the IEX/USDT PancakeSwap V2 pool.

Technical root cause

`IEXCBP.withdraw()` used `pancakeRouter.getAmountsOut(_usdAmount, [USDT, IEX])` as a raw spot-price oracle for a thin PancakeSwap V2 pool, making the withdrawal calculation manipulable in one transaction.

How it happened

The attacker used flash-loaned USDT to manipulate a thin IEX/USDT PancakeSwap V2 pool, then invoked the contract withdrawal path that priced IEX from the manipulated spot rate before dumping the drained tokens back into the pool.

Protocol details

Classification Oracle Manipulation
Protocol Type DeFi Protocol
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.