PancakeSwap liquidity provider loses about $2.96 million in malicious EIP-7702 authorization

PancakeSwap liquidity provider loses about $2.96 million in malicious EIP-7702 authorization

Specter said the long-inactive wallet was drained of roughly equal BSC-USD and BUSD liquidity, with part of the proceeds moved through Tornado Cash and the rest still held in USDT.

ETH
USDT
CAKE

Summary

A long-inactive PancakeSwap liquidity provider lost about $2.96 million after signing a malicious EIP-7702 authorization, Specter said. The attacker removed roughly $1.48 million in BSC-USD and another $1.48 million in BUSD liquidity, then swapped the BUSD for ETH. About $1.46 million was deposited into Tornado Cash, while roughly $1.48 million remained held in USDT. The incident highlights how malicious signing requests can let attackers seize funds from wallets that interact with DeFi protocols.

Terms & Concepts
  • EIP-7702 authorization: A wallet permission standard that can authorize specific on-chain actions.
  • liquidity provider: A user who supplies tokens to a trading pool.
  • Tornado Cash: A crypto mixing service that obscures fund transfers.