Frontrun attack called 'CPIMP' on BSC stole ~$1,000 from victim wallet via transaction manipulation.
Security & Exploits ·
A wallet on the Binance Smart Chain was targeted by a frontrunning attack labeled "CPIMP," resulting in approximately $1,000 in losses. The attack involved transaction manipulation designed to execute ahead of the victim's transaction, allowing funds to be intercepted before the legitimate transfer could complete. An on-chain message identified the attacker address and flagged the victim proxy contract involved in the incident.
Frontrunning attacks on decentralized exchanges and liquidity pools exploit the transparent nature of blockchain mempools, where pending transactions are visible before confirmation. In this case, the attacker monitored the victim's transaction, crafted a competing transaction with higher gas fees or strategic ordering, and extracted value through transaction reordering.
The exact mechanics of how the CPIMP attack achieved the fund extraction—whether through sandwich attacks, direct contract manipulation, or another vector—remain unspecified in the available alert. Similarly, it is unclear whether the $1,000 figure represents the total funds at risk, the amount actually stolen, or an estimate, and no information exists on whether the victim has pursued recovery or whether the attacker address has been traced further.