A public burn function introduced in the latest upgrade allegedly allows users to burn tokens from other addresses.
SafeMoon, a project previously endorsed by celebrities and social influencers like Jake Paul and Soulja Boy, announced its liquidity pool (LP) had been compromised. Without revealing further details about the attack, SafeMoon confirmed it is undertaking steps “to resolve the issue as soon as possible.”
Like many other crypto projects in 2021, SafeMoon was backed by numerous celebrities. However, a lawsuit from February 2022 alleged that musicians such as Nick Carter, Soulja Boy, Lil Yachty, and YouTubers Jake Paul and Ben Phillips mimicked real-life Ponzi schemes by misleading investors to purchase SafeMoon (SAFEMOON) tokens under the pretext of unrealistic profits.
Investigating the SafeMoon hack shows that the attacker made away with approximately 27,000 BNB, worth $8.9 million. SafeMoon has not yet responded to Cointelegraph’s request for comment. Moreover, users have been barred from posting comments on the announcement that revealed the LP compromise.
To the @SAFEMOON community: We want to inform you that our LP has been compromised.
We are taking swift action in an attempt to resolve the issue as soon as possible. Follow here for updates.
Thank you for your support as we work to address this situation.— SafeMoon (@safemoon) March 28, 2023
Blockchain investigator PeckShield narrowed the problem to a recent software upgrade as a potential culprit that introduced the bug. A public burn function introduced in the latest upgrade allegedly allows users to burn tokens from other addresses.
Community member “DeFi Mark” explained that the attacker used the vulnerability to remove SafeMoon tokens, causing an artificial spike in the token’s price. The attacker took advantage of the situation and sold off the tokens at an inflated price.
The attacker left a note along with the transaction, as shown above, which said:
“Hey relax, we are accidently frontrun an attack against you, we would like to return the fund, setup secure communication channel , lets talk.”
Until SafeMoon officially announces a resolution, investors are advised against investing in the project to avoid possible loss of funds.
On March 17-18th, 2023, GENERAL BYTES experienced a security incident.
We released a statement urging customers to take immediate action to protect their personal information.
We urge all our customers to take immediate action to protect their funds and https://t.co/fajc61lcwR…— GENERAL BYTES (@generalbytes) March 18, 2023
As Cointelegraph reported, the hack caused a loss of 56 BTC and 21.82 Ether, cumulatively worth nearly $1.9 million.