
Specter said the long-inactive wallet was drained of roughly equal BSC-USD and BUSD liquidity, with part of the proceeds moved through Tornado Cash and the rest still held in USDT.
A long-inactive PancakeSwap liquidity provider lost about $2.96 million after signing a malicious EIP-7702 authorization, Specter said. The attacker removed roughly $1.48 million in BSC-USD and another $1.48 million in BUSD liquidity, then swapped the BUSD for ETH. About $1.46 million was deposited into Tornado Cash, while roughly $1.48 million remained held in USDT. The incident highlights how malicious signing requests can let attackers seize funds from wallets that interact with DeFi protocols.