Wallet targeted by frontrun attack called CPIMP on Binance Smart Chain; funds stolen via transaction manipulation.
Security & Exploits ·
A wallet on Binance Smart Chain fell victim to a frontrunning attack labeled "CPIMP," in which a malicious actor manipulated transaction ordering to extract funds before the victim's transaction could execute. The incident was flagged in an onchain message that identified the victim proxy address, the attacker's wallet, and the attack transaction hash.
Frontrunning attacks exploit the mempool by observing pending transactions and inserting competing transactions with higher gas fees to execute first, allowing attackers to profit from transaction ordering. In this case, the CPIMP attack specifically manipulated a victim's interaction with a smart contract, redirecting or intercepting the funds before they reached their intended destination.
The alert cautioned against further use of the targeted contract, but no details have emerged regarding the total amount stolen, the specific mechanism by which the funds were diverted, or whether the attacker has been identified beyond their wallet address. The status of any recovery efforts or analysis by security researchers remains unclear.