BFBToken's price-defense mechanism exploited via repeated zero-value self-transfers to drain $198K WBNB from the BFB/WBNB LP pool over 151 flash-loan rounds.
Security & Exploits ·
BFBToken experienced a ~$198K loss on BNB Chain after its price-defense mechanism was exploited through repeated zero-value self-transfers. The token's _priceDeflPool() function was designed to burn 5% of the BFB/WBNB liquidity pair's BFB balance and call sync() whenever spot price dropped more than 5% below a stored threshold, intended to support the token's price. However, the mechanism's guard condition only checked that both sender and recipient were not contracts, allowing an attacker to trigger the burn repeatedly via EOA-to-EOA zero-value transfers between flash-loan-funded swap rounds.
Over approximately 151 rounds, the attacker systematically depleted the pair's BFB reserve by repeatedly invoking the burn mechanism, which removes BFB tokens from liquidity while shrinking the reserve and artificially inflating BFB's quoted price. This collateral damage to the pool's token ratio eventually allowed negligible amounts of BFB to be exchanged for disproportionately large quantities of WBNB from the pair.
The exploit resulted in approximately 350.6 WBNB (~$198K at $0.0297 per BFB) being withdrawn from the BFB/WBNB liquidity pool. The vulnerability stemmed from inadequate validation of the price-drop trigger, which did not account for the possibility of legitimate-looking internal transfers being weaponized to repeatedly activate the burn without requiring actual price movement.