LpdFi exploited for $690K via unguarded oracle price manipulation and flash loan attack on BNB Chain.
Security & Exploits ·
LpdFi suffered a loss of approximately $690K on BNB Chain after an attacker exploited a vulnerability in the protocol's price oracle mechanism. The attack combined a flash loan with direct manipulation of the PancakeSwap LPD/USDC pair reserves. LpdFi's price function derived token value directly from the spot reserves of this pair without time-weighted average price protection or safeguards against manipulation, creating an opening for the exploit.
The attacker used a flash-borrowed USDC amount to artificially skew the pair's reserve ratio, then triggered a claim that valued accrued interest far above what the underlying collateral warranted. When the protocol's claimInterest function executed, it withdrew liquidity by burning its own PancakeSwap LP position and distributed the proceeds—approximately $693.5K in USDC—to the attacker in a single transaction. The entire LpdFi LP stack, totaling approximately 1.68M LP tokens, was drained in the process.
The transaction and attacker address are recorded on-chain. It remains unclear whether LpdFi has published a post-mortem, whether affected users can recover funds, or what steps the protocol plans to prevent similar attacks.