RPP Hack
What happened
On November 5, 2024 an attacker used a flash loan to drain about $14,100 in BSC-USD from the PancakeSwap pool of the RPP token on BNB Chain. TenArmor found that anyone could make the RPP contract burn tokens held by its liquidity pair just by transferring RPP to that pair. A lastLpBurnTime variable seems to have been meant to limit how often this burn could run in autoLiquidityPairTokens, but it was never used. Each burn shrank the pool's RPP reserve and raised the RPP price inside the pool, so the attacker could sell RPP back for more BSC-USD than it had paid.
Attacker: 0x709b30b69176a3ccc8ef3bb37219267ee2f5b112
Attack contract: 0xfebfe8fbe1cbe2fbdcfb8d37331f2c8afd2a4b45
Attack tx: 0x76c39537374e7fa7f206ed3c99aa6b14ccf1d2dadaabe6139164cc37966e40bd
How it happened
- The attack contract flash-borrowed 1,200,000 BSC-USD from a PancakeSwap V3 pool.
- It bought RPP from the PancakeSwap V2 RPP/BSC-USD pair in 1,450 separate swaps.
- It then sold RPP back to the pair in repeated chunks. Per TenArmor, each transfer of RPP into the pair let the token burn RPP from the pair with no working rate limit, cutting the pair's RPP reserve and raising the price paid for the next sale.
- After the loop, it repaid the flash loan plus fee and sent the remaining BSC-USD, about $14,100, to the attacker.
Protocol details
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.