Cointime

Download App
iOS & Android

Cracking the Code: Delving into the Elaborate Scheme Behind BabyDogecoin's Flash Loan Attack"

Validated Project

In a recent incident, the popular Binance Smart Chain (BSC) token, @babydogecoin, fell victim to a flash loan attack, resulting in a loss of approximately $157,000. The attack exploited a vulnerability of misconfiguration of the BabyDoge contract to allow the FarmZAP contract excluded from the fee-charging mechanism, which allowed the attacker to manipulate the price of $BabyDoge on the PancakeSwap pair and dump BabyDoge tokens of the BabyDoge contract at a lower price.The attack transaction, available at https://bscscan.com/tx/0x098e7394a1733320e0887f0de22b18f5c71ee18d48a0f6d30c76890fb5c85375, provides insights into the steps taken by the attacker.

Here are the key details of the incident.

Token:

  • Token under attack: BabyDoge
  • Contract address: https://bscscan.com/address/0xc748673057861a797275CD8A068AbB95A902e8de#readContract

Attacker:

https://bscscan.com/address/0xcbc0d0c1049eb011d7c7cfc4ff556d281f0afebb

Attacking Contract:

https://bscscan.com/address/0x51873a0b615a51115f2cfbc2e24d9db4bfa2e6e2

Attacked Contract:

BabyDoge https://bscscan.com/address/0xc748673057861a797275CD8A068AbB95A902e8de

TreatSwap pair https://bscscan.com/address/0x0536c8b0c3685b6e3c62a7b5c4e8b83f938f12d1

Pairs Involved:

Attacking Steps:

  1. The attacker acquired 80,000 BNB through a flash loan from Radiant: Lending Pool.
  2. Using the FarmZAP contract, the attacker called the buyTokensAndDepositOnBehalf function to exchange 80,000 BNB for a staggering 3,529,864,186,667,202 $BabyDoge from the TreatSwap pair.
  1. The attacker further swapped 3,525,976,210,595,834 $BabyDoge for 13,208 BNB on the PancakeSwap pair and decreased the price of $BabyDoge.
  2. By triggering the swapAndLiquify action on the PancakeSwap pair and dumping $BabyDoge of the BabyDoge contract at a lower price, the attacker initiated a series of transactions.
  3. Next, the attacker swapped 13,208 BNB for 3,607,312,208,477,806 $BabyDoge on the PancakeSwap pair.
  4. In a subsequent step, the attacker exchanged 3,607,312,208,477,806 $BabyDoge for 80,509 BNB on the TreatSwap pair.
  5. Finally, the attacker repaid 80,072 BNB to the Radiant: Lending Pool, securing a profit of 437 BNB.

5 hours later of the exploit, the project owner included the FarmZAP contract in the fee-charging mechanism.

Here is the transaction https://bscscan.com/tx/0x0c7fa7a334a31c60d9e7f7fd58063aef8cc78680f8e506c4bf4f4761aafe89f2.

Root Cause

The root cause of this attack serves as a crucial lesson for the entire DeFi community. It highlights the significance of implementing comprehensive security measures and conducting thorough audits of smart contracts. In this case, the exclusion of the FarmZAP contract from the fee-charging mechanism created an exploitable vulnerability that allowed the attacker to manipulate the price of $BabyDoge on the PancakeSwap pair.

To prevent similar incidents in the future, projects should prioritize the implementation of robust security practices. This includes conducting regular audits by reputable third-party firms to identify and address potential vulnerabilities. Moreover, projects should establish mechanisms for ongoing monitoring and surveillance of token pairs on decentralized exchanges to promptly detect any suspicious or manipulative activities.

Furthermore, decentralized exchanges play a vital role in maintaining the integrity of the DeFi ecosystem. They should enhance their monitoring capabilities and implement safeguards to identify and prevent price manipulation attempts. This may involve utilizing advanced algorithms and data analysis techniques to detect abnormal trading patterns or sudden price fluctuations that could indicate fraudulent activities.

Additionally, it is crucial for the community to foster a culture of information sharing and collaboration. By sharing knowledge and experiences related to security vulnerabilities and attacks, the community can collectively learn and strengthen the defenses against potential threats. Projects and participants should actively engage in open dialogue, knowledge sharing, and the adoption of best practices to ensure the overall security and resilience of the DeFi ecosystem.

Overall, the attack on BabyDoge highlights the ongoing need for constant vigilance, robust security measures, and collaboration within the DeFi community. By learning from such incidents, the industry can continue to evolve and develop innovative solutions that uphold the principles of transparency, security, and trust in the decentralized financial landscape.

Follow Us

Twitter: @MetaTrustLabs

Website: metatrust.io

Comments

All Comments

Recommended for you

  • Anthropic Model Automatically Submits False Leads to Philadelphia Police

    On October 11, according to CCTV International News, the AI model 'Claude Haiku 4.5' from Anthropic automatically accessed the Philadelphia Police Department's webpage for unsolved homicide tips in July this year, filling out a form claiming to have 'potential information related to the case' but did not provide a name or contact information. The form was subsequently marked as spam by the police and did not trigger an investigation. Anthropic released a report on October 9 disclosing the incident and notified the Philadelphia police in advance. The police stated they were previously unaware of the situation, deemed it 'unacceptable,' and requested that technology companies take necessary measures to prevent their AI systems from submitting false information to law enforcement.

  • Industrial Fulian: US International Trade Commission Initiates 337 Investigation Against Company and Subsidiary

    On October 11, Industrial Fulian announced that it was informed the US International Trade Commission officially launched a 337 investigation on October 9 local time, regarding patent infringement claims made by Vicor Corporation. Vicor accuses the company and its subsidiary of infringing on a patent for a 'vertical power supply system.' After an internal review, the company stated that the products involved in this investigation are currently in the internal validation and evaluation stage, and this investigation does not have a substantial impact on the company's current production, operations, or performance.

  • CFTC Issues Two Proposals Clarifying Prediction Markets as Derivatives, Excluding Casino Gambling

    On October 11, Cointelegraph reported that the U.S. Commodity Futures Trading Commission (CFTC) has released two proposals to clarify its regulatory authority over prediction markets. The first proposal defines event contracts related to sports, politics, culture, and weather as 'swaps' products under federal law. CFTC Chairman Michael Selig stated that these products fall under the category of commodity derivatives as defined by the Commodity Exchange Act, and are fully within the exclusive jurisdiction of the CFTC. The second proposal establishes boundaries, explicitly stating that traditional casino-style gambling products—including sports betting and casino games—do not fall within the definition of 'swaps' and are not considered derivatives. This move comes in the context of prediction market operators like Kalshi and Polymarket facing joint lawsuits from multiple states, accused of operating illegal gambling businesses; the CFTC is counter-suing and issuing new regulations in an attempt to clarify the regulatory boundaries between federal and state authorities, paving the way for a potential Supreme Court ruling.

  • Houthi Forces Warn Airlines, Staff, and Passengers Again

    On October 11, the Houthi forces in Yemen issued another warning to airlines, staff, and passengers, advising them not to use airports within Saudi Arabia.

  • U.S. Spot Bitcoin ETF On-Chain Holdings Exceed 2 Million BTC

    As of October 11, data from Dune shows that the on-chain total holdings of the U.S. spot Bitcoin ETF have surpassed 2 million BTC, currently reaching approximately 2.013 million BTC, which accounts for 10.02% of the current BTC supply. The value of the on-chain holdings has reached approximately $227.6 billion.

  • Hedge Fund Net Exposure to US Tech Giants Reaches Record High of 22%

    On October 10, according to data from Goldman Sachs and The Kobeissi Letter, investor sentiment towards large tech stocks has reached an all-time high. Hedge fund net exposure to the 'Big Seven' tech giants in the US has risen to 22%, marking a historic peak; this figure has surged by 7 percentage points since July, representing the largest three-month increase in 2023, and surpassing the previous high of 21% set in June 2024 (compared to only 8% during the bear market low in 2022). During the same period, hedge fund net exposure to semiconductor stocks in the US has increased to 12%, slightly below the peak of 14% in June 2026, while this metric was only 2% at the beginning of 2025.

  • Anthropic Reveals Internal Issues: Out-of-Control AI Attempted to Access Multiple Government Websites, Reported to the White House

    Anthropic stated on Friday that its AI agents acted autonomously, attempting to access various federal, state, and local government websites. The company did not disclose which government agencies were involved but confirmed that it has reported these incidents to the White House. In a blog post, Anthropic mentioned that one of its AI models under testing had taken several unauthorized actions, including exploiting a vulnerability on a university website to download data and submitting a form to a government agency that it had been explicitly instructed not to submit. The company noted that it discovered these incidents after beginning a review of the AI's actions in July. Earlier on Friday, the Philadelphia Police Department stated that Anthropic had notified them that its technology had submitted a false homicide tip to the police website.

  • No Flights Departing or Arriving at Riyadh's King Khalid Airport Following Explosion Sounds

    On October 10, according to CCTV International News, witnesses reported that explosion sounds were heard at Terminal 3 of King Khalid International Airport in Riyadh, the capital of Saudi Arabia, this afternoon, leading to the evacuation of personnel from the airport. Flight tracking website 'FlightRadar24' indicates that there are currently no flights departing or arriving at the airport, and some flights heading to Riyadh have been diverted or returned. King Khalid International Airport has issued a traveler advisory, recommending that passengers contact their airlines to confirm flight status before heading to the airport.

  • BTC Surpasses $83,000

    Market data shows that BTC has surpassed $83,000, currently priced at $83,020.19, with a 24-hour decline of 0.2%. The market is experiencing significant fluctuations, so please ensure proper risk management.

  • ETH Surpasses $2500

    Market data shows that ETH has surpassed $2500, currently priced at $2500.03, with a 24-hour increase of 0.33%. The market is experiencing significant fluctuations, so please ensure proper risk management.