Z123 Hack

Reported loss $136K
BNB Chain
Spot Price Manipulation

What happened

On April 22, 2024, an attacker drained about $135-136K in BSC-USD (USDT) from the Z123/USD liquidity pair on BNB Smart Chain. The Z123 token (SesameCloudToken) has a minter-only update(pair, amount) function that moves Z123 straight from the pair to the dead address. The project's own swap router called it after every sell to burn 2,850 Z123 from the pool, then called sync(). Each burn removed Z123 from the pool without taking out any USD, so every later sell through that router received more USD than a normal constant-product swap would pay.

The attacker used an 18,000,000 USD flash loan to buy a large Z123 position, sold it back through the project router in 79 fixed-size sells, and repaid the loan with the profit left over. PeckShield flagged the exploit at about $136K.

How it happened

  1. The attacker (0x3026C464d3Bd6Ef0CeD0D49e80f171b58176Ce32) flash-borrowed 18,000,000 BSC-USD from a PancakeSwap V3 pool.
  2. It bought about 575K Z123 through a normal router, pushing a large USD balance into the Z123/USD pair.
  3. It sold 7,125 Z123 through the project's custom router 79 times. After each sell, the router called Z123.update(pair, 2850e18), which moved 2,850 Z123 out of the pair to 0x...dEaD, and then called pair.sync().
  4. Each sync() locked in a smaller Z123 reserve while the USD reserve was untouched. That moved the price in the seller's favor, so each identical sell drew out more USD.
  5. The attacker repaid 18,009,000 BSC-USD (loan plus 0.05% fee) and kept about $135K (tx 0xc0c4e99a...3a6a27).

Protocol details

Classification Oracle Manipulation
Protocol Type Token
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.