What happened
A PancakeSwap liquidity provider has lost approximately $2.96 million after signing a malicious EIP-7702 authorization, according to on-chain security monitor Specter. The victim, a long-dormant LP, had their funds drained by an attacker who exploited the signed authorization to remove liquidity and convert assets.
Why it matters for the market
The attacker removed roughly $1.48 million in BSC-USD and $1.48 million in BUSD from the victim's position. The BUSD was subsequently swapped for ETH. As part of the laundering process, the attacker deposited about $1.46 million into Tornado Cash, while approximately $1.48 million in USDT remains in the attacker's wallet.
This incident highlights the risks associated with signing EIP-7702 authorizations, which can grant attackers control over assets if signed maliciously. The attack underscores the importance of verifying authorization requests, especially for liquidity providers with significant holdings.
What traders should watch
The market impact of this event is considered negative, as it may erode trust in DeFi protocols and increase caution among LPs. However, the direct effect on PancakeSwap's overall liquidity and token price is likely limited given the isolated nature of the attack.
0
0
0
0