Legend Coin Incident Analysis
ID: e8ac6037-cd3f-59ef-9f5b-ff7449632c0e
STIX ID: report--e8ac6037-cd3f-59ef-9f5b-ff7449632c0e
Feed Name: CertiK Blog
On 23 May 2022 an attacker exploited a smart-contract coding error in Legend Coin (LDC) by using an 11 BNB flash loan and LP manipulation (skim/sync) to profit ~$153. The vulnerability arose because liquidity pool addresses were not excluded from a 6% transfer fee, causing token imbalance when LPs transferred tokens between pools; this allowed the attacker to manipulate prices and extract funds. The incident demonstrates a low-dollar but high-risk pattern in DeFi contracts and underscores the need for proper fee exclusions and audits.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
