According to the monitoring of the Beosin EagleEye platform, the Cupid token contract on the BNB Chain was attacked by flash loans. The Beosin security team analyzed and found that the Cupid contract 0x40c994299fb4449ddf471d0634738ea79c734919 has a reward logic loophole. LP tokens with USDT/VENUS can get Cupid tokens. The attacker uses flash loan to lend USDT, buys VENUS tokens, and obtains LP tokens after mortgage. After sending LP to multiple addresses, he obtains Cupid tokens by calling the 0xe98bfe1e() function claim of the attacked contract, and sells them after obtaining Cupid tokens. Profit 78623 USDT.