SEAMAN Hack

Reported loss $7K
BNB Chain
Unknown

What happened

On November 29, 2022 an attacker used a flash loan to take about $7.8K from the pools around the SEAMAN token on BNB Chain. SEAMAN charged trading taxes and paid holders a dividend in another token, GVC. Whenever any amount of SEAMAN was sent to the SEAMAN/USDT pair, the token's _transfer hook ran swapAndLiquifyV3() and swapAndLiquifyV1(). These sold the contract's accumulated tax SEAMAN along the fixed path SEAMAN to USDT to GVC with no minimum output, which meant buying GVC in a small USDT/GVC pool.

Because anyone could trigger that swap with a 1-wei transfer, as many times as they liked, an attacker could force the contract to keep buying GVC and push its price up. CertiK described it as a flaw in how SEAMAN handled GVC distribution; Fairyproof said the tokenomics design allowed price manipulation. PeckShield noted that GVC dropped about 81% after the attack.

Attack tx: 0x6f1af27d08b10caa7e96ec3d580bf39e29fd5ece00abda7d8955715403bf34a8 Attacker: 0x49fac69c51a303b4597d09c18bc5e7bf38ecf89c (per Fairyproof)

How it happened

  1. The attacker borrowed 800,000 USDT from a DODO pool using a flash loan.
  2. They bought a dust amount of SEAMAN, then spent 500,000 USDT on about 485,908 GVC in the USDT/GVC pool.
  3. They sent 1 wei of SEAMAN to the SEAMAN/USDT pair 20 times. Each transfer made the SEAMAN contract sell part of its tax balance for GVC, buying GVC in the same pool and pushing the GVC price higher.
  4. They sold their GVC back for about 507,782 USDT at the inflated price, repaid the 800,000 USDT loan and kept about 7,782 USDT.

Protocol details

Classification Protocol Logic
Protocol Type Token
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.