An unknown USDC-OCA liquidity pool on the BSC chain was attacked, leading to the extraction of approximately 422,000 USDC. According to PANews, the attacker exploited a vulnerability in the deflationary sellOCA() logic of the OCA token, which allowed them to artificially inflate the token price by removing an equivalent amount of OCA from the pool during each swap.
The attack was executed through three transactions: the first carried out the attack operation, while the latter two were primarily used to pay additional bribes to block builders. The attacker paid a total of approximately 43 BNB and 69 BNB to 48club-puissant-builder, ultimately profiting an estimated $340,000. Another transaction within the same block failed at position 52, suspected to have been front-run by the attacker.