PancakeSwap 79AU Pool Loses $14.35M Despite Locked Liquidity

iconCryptoSlate
Share
AI summary iconSummary
On-chain news reveals that the PancakeSwap 79AU pool lost $14.35 million in USDT on October 7 via two wallets, per Bitquery. The token, part of a new token listing on the platform, allowed removal of tokens without payment, bypassing liquidity receipts. Over 79% of liquidity-provider receipts were burned, leaving the pool exposed. The incident highlights risks in permission structures for new token listings.

The PancakeSwap pool for 79AU, 79thVault’s token, lost $14.35 million in USDT on Oct. 7 through two selling wallets, according to a Bitquery investigation published Oct. 8.

Bitquery found that 79% of the pool’s liquidity-provider receipts had been burned. But a permission inside 79AU let tokens leave the pool without payment. Those tokens were then sold back for USDT, bypassing the need to redeem a liquidity receipt.

Related Reading

Crypto hackers exploit third-party Aave tool to steal 114 ETH

PancakeSwap’s V2 documentation describes LP tokens as receipts representing a provider’s share of a pool. They are separate from the two assets traders exchange inside it.

The exchange’s liquidity guide describes ordinary redemption: a provider selects a share to remove and receives both paired tokens. Sending receipts to an inaccessible address prevents their redemption. It does not disable swaps, since trading exchanges the underlying assets without cashing in a liquidity position.

In PancakeSwap’s archived pair contract, separate operations handle LP redemption, swaps and updating recorded reserves to match token balances. The swap operation checks token input without consuming LP receipts. The reserve-update operation reads balances from the underlying token contracts. Burning LP receipts does not rewrite those contracts’ balance rules or revoke a privileged address’s token permissions.

Related Reading

Base’s Cobalt upgrade adds another rule to affect token balances

What remained exposed

At 12:53 UTC on Oct. 8, Bitquery identified two pull-authorized addresses: the deployer and a newly authorized wallet. Read-only simulations from either allowed removal of about 95% of the pool’s remaining 79AU. The read-only tests moved no funds.

The same snapshot showed one wallet holding the unburned 21% of LP receipts, with ordinary redemption rights over that share.

Related Reading

Cardano’s Splash fix patches the exploit, but leaves 2.4M ADA missing and holders trapped

Establishing whether 79AU’s reported exposure has ended requires a fresh check of that transfer permission.

The post Locked liquidity did not stop this $14 million crypto pool drain appeared first on CryptoSlate.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.