Space Dumpling Incident Analysis
ID: 9f9e89b1-806c-5dec-b015-a433debbd7e7
STIX ID: report--9f9e89b1-806c-5dec-b015-a433debbd7e7
Feed Name: CertiK Blog
On May 15, 2022 Space Dumpling (SDUMP) was exploited via a flash-loan attack that abused an anti‑whale transfer-fee bug in the token contract, enabling an attacker to repeatedly force SDUMP liquidity pools to overpay tokens and extract ~7.6 BNB across SDUMP-WBNB and SDUMP-BUSD pools; the attacker later obfuscated proceeds through Tornado Cash. The report includes transaction and attacker/contract addresses, a contract vulnerability analysis showing the fee was not deducted from transfer amounts, and notes the same attack pattern was used against multiple small tokens.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
