← Radar

Incident case file

Sign in to watch

LOOPSDAO LpdFi Flash Loan Price Manipulation

Incident date 2026-08-01Last updated Aug 14, 2026

1 views

ClosedBNB ChainFlash loan / price manipulationCluster: LPD-FLASH-2026-08

Estimated loss

$689.5K

Victims identified

more than ten victims identified
Victim group joining is coming soon.

Investigation

90%

Facts and investigation

Ledger

Attacker

0x5d289266d85EF671561bA3F253FB79327C193f33 (attacker EOA, on-chain verified); executor contract 0x7f5AD0A998Dcb3f5006F0D152BEBC055979EF711 (on-chain verified)

Funds moved to

689,529.793138448987344168 USDC (~$689,496.33 net) transferred to attacker EOA 0x5d289266d85EF671561bA3F253FB79327C193f33 in transaction 0x70bbe0aa3c7ef149ecb6128a06025885deaa8fef3f393a505d447d28ab3315d6 (block 113613924, BscScan-verified). A flash loan of 730,607.75 USDC was repaid to Uniswap V4 Pool Manager; approximately $7,005 was additionally routed to a fee-collection address (0x4c0c8604...a9C977242, partial address). A secondary flow of 4,000 USDC moved through intermediary 0xEc655734...6

Linked

Victim contract: LpdFi protocol 0xcE6A6e4413d85a136bbac8aae6fb46eaa77f295e (on-chain verified). Flash loan sourced from Uniswap V4 Pool Manager. Exploited liquidity pool: PancakeSwap V2 LPD-USDC (thin liquidity, no TWAP or price-deviation guard). Protocol burned 1,678,049.359669752344366455 of its own Cake-LP tokens as part of the exploit mechanism.

Chronology

1 beat
  1. T0 (August 2, 2026, block 113613924, BscScan transaction verified in full): Attacker 0x5d289266d85EF671561bA3F253FB79327C193f33 executes a flash loan of 730,607.75 USDC sourced from Uniswap V4 Pool Manager. The loan is used to manipulate the spot price of the thin PancakeSwap V2 LPD/USDC liquidity pool, which had no time-weighted average price (TWAP) mechanism or deviation guard protecting it. The attacker opens a massively inflated interest-bearing position within the LpdFi protocol using minimal actual LPD collateral, then claims accrued interest at precisely the daily settlement boundary. This action triggers the LpdFi protocol contract (0xcE6A6e4413d85a136bbac8aae6fb46eaa77f295e) to burn 1,678,049.36 of its own Cake-LP tokens and disburse 4,059,427.5 LPD tokens plus 700,535.14 USDC to the attacker's executor contract (0x7f5AD0A998Dcb3f5006F0D152BEBC055979EF711). The executor forwards approximately $693,496 onward to the attacker EOA, with roughly $7,005 skimmed off to a separate fee-collection address along the way. The attacker repays the original 730,607.75 USDC Uniswap V4 flash loan and swaps remaining proceeds back into WBNB via PancakeSwap Router v2. Final net proceeds retained by the attacker: $689,496.33. T+approximately 24 hours (August 3, 2026, 06:00:52 UTC): Security research group ExVul, via the Defimon Alerts monitoring account, publishes the first detailed public technical breakdown of the exploit, including on-chain addresses. The same day, Chainalysis (citing detection by Hexagate) independently confirms the incident, describing a roughly $44 million flash loan that inflated the LPD token's spot price by a factor of 71x before the attacker's claim. SlowMist Hacked and DeFiLlama log the incident at $690,000 and $696,000 respectively (both close to, but not identical to, the on-chain-verified net figure of $689,496.33). As of the close of the reporting window, no official post-mortem, patch announcement, or user compensation plan has been published by the LOOPSDAO/LpdFi team.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)