MBC & ZZSH Hack
What happened
On November 29, 2022, an attacker took about $5,900 from two related BNB Chain tokens, MBC and ZZSH, in one flash-loan transaction. Both tokens kept the fees taken on PancakeSwap trades in the token contract. A function called swapAndLiquifyStepv1() added those stored fees to the token's pool as liquidity.
It was public, had no access control and did not check the pool price first. The attacker skewed each pool, made the token add its fees at that skewed price, and sold back into the pool at a profit. CertiK saw MBC's price fall by more than 90% and put the attacker's gain at about $5K.
DeFiHackLabs lists $5.9K across both tokens.
How it happened
- The attacker flash-borrowed USDT from a DODO pool.
- It bought MBC with 150,000 USDT directly through the MBC/USDT pair, pushing the pool heavily toward USDT.
- It called
MBC.swapAndLiquifyStepv1(), which added the MBC contract's stored fees to the pair as liquidity at the manipulated ratio. - It sent its MBC back into the pair (with a 1,001-wei USDT transfer that the DeFiHackLabs PoC ties to the token's
_isAddLiquidityV1()check) and swapped it out for USDT, taking the value the fee liquidity had added. - It repeated steps 2-4 on the ZZSH/USDT pair with
ZZSH.swapAndLiquifyStepv1(), then repaid the flash loan. Attack tx:0xdc53a6b5bf8e2962cf0e0eada6451f10956f4c0845a3ce134ddb050365f15c86.
Protocol details
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.