IPC AI Hack
What happened
On January 7, 2025, an attacker drained about $590,000 in USDT from the IPC/USDT liquidity pair on BNB Chain by abusing the IPC token's own transfer logic. The token had been deployed about a week earlier. To push the price up, IPC burned tokens straight out of the liquidity pair on every sell, and it tried to block flash-loan trading by tracking the last transfer time of each address. CertiK reported that the attacker got around the flash-loan protection and used the burn mechanism to take funds from the pair.
DeFiHackLabs labels transaction 0x5ef1edb9749af6cec511741225e6d47103e0b647d1e41e08649caaff66942a91 as a front-run of an earlier attack attempt (0x3a3683119e1801821faa15c319cb9c8fb3fcf6ee92b1904a829d82c432e09a44), so the address that profited may have copied someone else's exploit. No recovery has been reported.
How it happened
- The attacker flash-borrowed USDT from DODO pools.
- Instead of trading through the router, the attacker called the pair's low-level
swap()directly. IPC therefore did not treat the trade as a normal buy,transferTime[sender]stayed at 0 so the flash-loan check did not trigger, and the buy paid no fee. - On selling, IPC's
_destroy()logic burned roughly half of the last sell amount directly from the pair's IPC balance, but it did not sync the pair's stored reserves. - With the pair's real balances out of line with its reserves, the attacker called
swap()again and took out both tokens, getting far more USDT than they had put in. - The attacker repaid the flash loans and kept about $590,000 USDT.
Protocol details
Evidence
- code DeFiHackLabs: 20250107 IPC Incorrect burn pairs - Logic Flaw (IPC_exp.sol) github.com
- analysis DeFiLlama defillama.com
- analysis Jan 2025 - IPC Token TransferTime Swap Contract Vulnerability (Quadriga Initiative) quadrigainitiative.com
- analysis CertiK Alert: The IPC token deployed 7 days ago has a vulnerability (ChainCatcher, 2025-01-08) chaincatcher.com
- analysis xnpcs.ai page xnpcs.ai xnpcs.ai
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.