Frontrun attack called CPIMP on BSC stole approximately $11,000 from a victim via transaction manipulation.
Security & Exploits ·
A frontrun attack designated "CPIMP" on Binance Smart Chain targeted a user's transaction, resulting in the theft of approximately $11,000 according to an onchain alert. The attack manipulated transaction ordering to execute the attacker's transaction ahead of the victim's, allowing funds to be redirected before the legitimate transfer could complete.
Frontrun attacks exploit the public nature of the blockchain mempool, where pending transactions are visible before confirmation. An attacker observing a profitable transaction can insert their own transaction with a higher gas fee to achieve priority execution, intercepting or draining value from the target transaction. The CPIMP variant appears to operate through a proxy contract mechanism to obscure the attack vector.
The specific addresses and transaction hashes involved have been documented onchain, though it remains unclear whether the attack exploited a vulnerability in a particular protocol, a user interaction pattern, or a broader smart contract design flaw. No statement from affected projects or security researchers analyzing the attack mechanism has been provided.