CashCowCoin exploited via oracle manipulation and flash loan for $117K loss on BNB Chain.
Security & Exploits ·
CashCowCoin suffered a loss of approximately $117,000 on BNB Chain on August 27, 2026, through an oracle manipulation attack leveraging a flash loan. The attacker exploited the token's pricing mechanism, which relied on spot reserves from the CCC/WBNB Pancake pair, by flash-loaning roughly 416,831 WBNB from a Moolah lending market and depositing it directly into the pair before triggering a sync() call to artificially inflate its reserve balances.
With reserves artificially elevated, the attacker executed a series of buy and sell transactions against the manipulated price, draining real liquidity from the CCC/WBNB pair. The pair's WBNB reserves fell from approximately 165.5 WBNB to roughly 0.018 WBNB, allowing the attacker to extract value before repaying the flash loan. After loan repayment, the attacker retained approximately 165.47 WBNB, equivalent to the $117,000 loss.
The vulnerability stemmed from the protocol's reliance on getReserves() for real-time pricing without safeguards against momentary manipulation. No protective mechanisms such as time-weighted average price oracles or flash loan guards appear to have been implemented to defend against this vector.