Sebuah 'Ledakan Diri' yang Dirancang dengan Cermat: Analisis Serangan PGNLZ

marsbitPublished on 2026-01-28Last updated on 2026-01-28

Abstract

**Analisis Serangan PGNLZ: Eksploitasi Model Ekonomi Deflasioner** Pada 27 Januari 2026, sebuah serangan canggih terjadi pada proyek **PGNLZ** di BNB Smart Chain, mengakibatkan kerugian sekitar **$100.000 USD**. Penyerang memanfaatkan model token deflasioner proyek untuk memanipulasi harga dan menguras pool likuiditas. **Langkah-Langkah Serangan:** 1. Penyerang meminjam flash loan **1.059 BTCB** dari Moolah Protocol. 2. BTCB dijadikan jaminan di Venus Protocol untuk meminjam **30.000.000 USDT**. 3. Sebagian besar USDT (23.337.952) digunakan untuk membeli **982.506 PGNLZ** di PancakeSwap, yang kemudian dikirim ke alamat mati (`0xdead`) untuk **dihancurkan (burn)**. Tindakan ini secara drastis mengurangi suplai token dalam pool. 4. Penyerang kemudian memicu fungsi penjualan (`swapExactTokensForTokensSupportingFeeOnTransferTokens`), yang mengaktifkan mekanisme `_executeBurnFromLP` dalam kontrak. 5. Fungsi ini membakar jumlah PGNLZ yang sangat besar (`pendingBurnFromLP`) dari pool likuiditas, menyisakan hanya **0.00000001 PGNLZ**. 6. Pembakaran masif ini menyebabkan harga PGNLZ melonjak **40 miliar kali lipat**, dari $0.1 menjadi $234 triliun per token. 7. Dengan harga yang dimanipulasi, penyerang mengosongkan pool likuiditas yang tersisa, melunasi pinjaman flash loan, dan meraup keuntungan. **Akar Masalah:** Kerentanan utama terletak pada **model ekonomi deflasioner** yang tidak memiliki pemeriksaan yang memadai saat membakar token dari pool likuiditas. Hal ini memungk...

Latar Belakang

Pada 27 Januari 2026, kami memantau serangan terhadap proyek PGNLZ di BNB Smart Chain:

https://bscscan.com/tx/0xa7488ff4d6a85bf19994748837713c710650378383530ae709aec628023cd7cc

Setelah analisis mendetail, penyerang secara terus-menerus melancarkan serangan terhadap proyek PGNLZ pada 27 Januari 2026, serangan ini menyebabkan kerugian sekitar 100 ribu USD.

Analisis Serangan dan Peristiwa

Penyerang pertama-tama meminjam flash loan sebesar 1.059 BTCB dari Moolah Protocol,

Kemudian, menjaminkan 1.059 BTCB di Venus Protocol, untuk meminjam (borrow) 30.000.000 USDT.

Selanjutnya, penyerang memanggil fungsi swapTokensForExactTokens di PancakeSwap, menggunakan 23.337.952 USDT untuk menukar 982.506 PGNLZ, tetapi kemudian menghancurkan (burn) PGNLZ ini (dikirim ke alamat 0xdead).

Sebelum penukaran, PancakeSwap Pool memiliki 100.901 USDT dan 982.506 PGNLZ, saat itu harga PGNLZ adalah 1 PGNLZ = 0,1 USDT. Setelah penukaran selesai, PancakeSwap Pool menyisakan 23.438.853 USDT dan 4.240 PGNLZ, saat ini harga PGNLZ adalah 1 PGNLZ = 5.528 USDT.

Kemudian, penyerang memanggil fungsi swapExactTokensForTokensSupportingFeeOnTransferTokens, fungsi ini terutama mendukung Token dengan Biaya Transfer (Fee-On Transfer Token), yaitu token yang dikenakan biaya saat jual beli. PGNLZ menggunakan _update untuk menangani biaya transaksi, rantai panggilannya adalah: transferFrom -> _spendAllowance -> _transfer -> _update

Karena kali ini adalah penjualan (sell), maka akan memanggil _handleSellTax.

Mari kita lihat bagaimana _executeBurnFromLP diimplementasikan,

Dapat dilihat, _executeBurnFromLP akan menggunakan _update untuk membakar (burn) sejumlah PGNLZ sebanyak pendingBurnFromLP. Pada blok sebelumnya, query menunjukkan pendingBurnFromLP adalah 4.240.113.074.578.781.194.669.

Setelah pembakaran (burn), LP Pool hanya menyisakan 0,00000001 PGNLZ, saat ini 1 PGNLZ = 234.385.300.000.000 USDT, telah naik 40 Miliar kali lipat.

Akhirnya, penyerang mengosongkan LP Pool, melunasi pinjaman flash loan, dan mendapatkan keuntungan 100 ribu USDT.

Kesimpulan

Penyebab kerentanan ini adalah model ekonomi deflasioner, yang tidak melakukan verifikasi saat memotong biaya atau membakar LP Pool. Hal ini memungkinkan penyerang memanipulasi harga Token dengan memanfaatkan karakteristik deflasioner. Disarankan agar pihak proyek melakukan verifikasi多方验证 (berbagai verifikasi) dalam merancang model ekonomi dan logika operasional kode, serta memilih beberapa perusahaan audit untuk audit silang sebelum kontrak diluncurkan.

Related Questions

QApa yang menjadi penyebab utama kerentanan dalam proyek PGNLZ yang dieksploitasi oleh penyerang?

APenyebab utamanya adalah model ekonomi deflasioner yang tidak memvalidasi proses pemotongan biaya atau pembakaran (Burn) dari Liquidity Pool (LP), memungkinkan penyerang memanipulasi harga token melalui karakteristik deflasi.

QBagaimana penyerang memanipulasi harga token PGNLZ hingga naik miliaran kali lipat?

APenyerang membakar sejumlah besar PGNLZ (982.506 token) ke alamat 0xdead, mengurangi pasokan di pool secara drastis. Kemudian, melalui fungsi _executeBurnFromLP, hampir semua sisa PGNLZ di pool dibakar, menyisakan hanya 0.00000001 token, sehingga harga naik sekitar 40 miliar kali.

QPlatform apa saja yang digunakan penyerang untuk melakukan serangan ini?

APenyerang menggunakan Moolah Protocol untuk pinjaman kilat (flash loan) BTCB, Venus Protocol sebagai jaminan untuk meminjam USDT, dan PancakeSwap untuk melakukan pertukaran token dan memanipulasi pool likuiditas PGNLZ/USDT.

QBerapa total kerugian yang disebabkan oleh serangan ini terhadap proyek PGNLZ?

ASerangan ini menyebabkan kerugian sekitar 100.000 USD.

QApa rekomendasi yang diberikan untuk mencegah serangan serupa di masa depan?

ARekomendasinya adalah memvalidasi model ekonomi dan logika kode secara menyeluruh, serta melakukan audit oleh beberapa perusahaan audit berbeda (audit silang) sebelum kontrak deploy ke mainnet.

Related Reads

Uncovering the Truth About Agent Commerce, Payments, and Infrastructure

Decoding Agent Commerce, Payments, and Infrastructure: The Reality Over the past year, I've been building infrastructure for the Agent economy, engaging with major players like Stripe, Visa, Coinbase, Google, and dozens of startups. A clear conclusion emerges: true, large-scale demand does not yet exist. Startups face structural challenges. Data points illustrate this gap. Stripe's Agent commerce platform has over 1,000 merchants but only single-digit transacting agents. Visa's Agent payment token requires 9-month KYC and a $250M revenue threshold, accessible only to giants like Amazon. On-chain analysis reveals actual daily Agent transaction volume is around $17k, half of which are test transactions. The article analyzes four potential markets: **1. Agent-to-Merchant (A2M):** Current AI shopping UX is often inferior to traditional e-commerce for visual, comparison-heavy purchases (clothing, electronics). Chat interfaces are a step back. Real merchant interest is defensive "Agent Engine Optimization," fearing future obsolescence, not current demand. Potential exists in high-frequency, low-decision purchases (e.g., food delivery) or simplifying terrible UX (complex checkouts, non-native shoppers), but these require massive consumer distribution channels dominated by giants like DoorDash and Amazon. **2. Agent-to-API (A2A):** Developers already have subscriptions and billing for core APIs (compute, data). The argument for micro-payments via crypto for sub-dollar API calls is addressed by pre-paid balances today. The deeper issue is supplier resistance; major SaaS firms rely on enterprise contracts, not fractional cent pricing. Opportunity lies in the long tail of niche services, but this is a smaller market catering to developers, a historically low-paying group. **3. Agent-to-Agent (A2A):** This remains a theoretical long-term vision with near-zero current transaction volume. It involves unique challenges: discovery, trust, negotiation, dispute resolution. When it materializes, it will require a fundamentally new settlement infrastructure for high-speed, variable-value, multi-party transactions. It's a real long-term bet, but not the current market. **4. Agent-to-Finance (A2F):** This is the only category with existing, paying demand. Integrating AI into financial workflows (trading, portfolio management) is a natural evolution and enables new capabilities like autonomous rebalancing. However, competition favors incumbents with regulatory licenses, compliance infrastructure, and existing client relationships. **The Real Issue:** Why is infrastructure still being built? Incumbents can afford long-term bets, and payment companies see every problem as a nail for their payment hammer. However, payment is just one piece. The core challenge is *coordination*—orchestrating work between Agents and humans, verifying outcomes, and settling results. Payment is part of settlement, which is part of coordination. Companies that solve the coordination problem will subsume payments, not the other way around. Startups lack the infinite runway of giants and must find today's real market, which, after a year of exploration, lies outside these four categories—in an area with real, growing, and underserved activity.

marsbit1h ago

Uncovering the Truth About Agent Commerce, Payments, and Infrastructure

marsbit1h ago

Kalshi, MTS, and a16z's Ambition

The article "Kalshi, MTS, and a16z's Ambition" explores prediction markets as a focal point of excitement in 2025 for investors, crypto enthusiasts, and media. It traces their intellectual lineage from Friedrich Hayek's ideas on dispersed knowledge and market coordination to Robin Hanson's Logarithmic Market Scoring Rule (LMSR), which incentivizes truthful information sharing. The piece argues that a16z's significant investment in prediction market platform Kalshi (valued at $220B) transcends mere financial speculation. a16z frames prediction markets as a new form of "media" that provides "presence"—a way for individuals to actively engage with and influence world events through financial stakes, countering postmodern detachment. By wagering on outcomes, users become "super observers," and the market's aggregated probabilities gain authoritative power to define event truth and importance. The article uses media company MTS ("Monitoring The Situation") as a case study of a16z's "new media" strategy: rapidly producing high-intensity, multi-format content to "take over the timeline." However, prediction markets like Kalshi are presented as the ultimate piece in this media empire. Their real-money, crowd-sourced probabilities possess a unique "reality distortion field" and perceived objectivity, potentially swaying public opinion and granting a private company unprecedented interpretive power over reality. Ultimately, Kalshi's immense valuation is attributed not just to its exchange model, but to its role as a foundational component in a16z's envisioned new media landscape, where prediction markets define narrative and truth.

链捕手1h ago

Kalshi, MTS, and a16z's Ambition

链捕手1h ago

Trading

Spot
Futures

Hot Articles

How to Buy WELL

Welcome to HTX.com! We've made purchasing Moonwell Artemis (WELL) simple and convenient. Follow our step-by-step guide to embark on your crypto journey.Step 1: Create Your HTX AccountUse your email or phone number to sign up for a free account on HTX. Experience a hassle-free registration journey and unlock all features.Get My AccountStep 2: Go to Buy Crypto and Choose Your Payment MethodCredit/Debit Card: Use your Visa or Mastercard to buy Moonwell Artemis (WELL) instantly.Balance: Use funds from your HTX account balance to trade seamlessly.Third Parties: We've added popular payment methods such as Google Pay and Apple Pay to enhance convenience.P2P: Trade directly with other users on HTX.Over-the-Counter (OTC): We offer tailor-made services and competitive exchange rates for traders.Step 3: Store Your Moonwell Artemis (WELL)After purchasing your Moonwell Artemis (WELL), store it in your HTX account. Alternatively, you can send it elsewhere via blockchain transfer or use it to trade other cryptocurrencies.Step 4: Trade Moonwell Artemis (WELL)Easily trade Moonwell Artemis (WELL) on HTX's spot market. Simply access your account, select your trading pair, execute your trades, and monitor in real-time. We offer a user-friendly experience for both beginners and seasoned traders.

2.3k Total ViewsPublished 2024.03.29Updated 2026.06.02

How to Buy WELL

What is $WELL

WELL3, $$WELL: Revolutionizing Health and Wellness with DePIN and AI Introduction In the rapidly evolving landscape of digital technology, the health and wellness sector stands at the forefront of innovation, striving to enhance patient care and promote healthier lifestyles. A groundbreaking player in this domain is WELL3, a pioneering Web3 project that seeks to revolutionize how individuals engage with their health. By leveraging technologies such as Decentralized Physical Infrastructure Network (DePIN), Decentralized Identity (DID), and Artificial Intelligence (AI), WELL3 aims to foster secure, data-empowered health journeys. This comprehensive article delves deep into the core aspects of WELL3, $$WELL, exploring its functionalities, creators, investors, and unique features. What is WELL3, $$WELL? WELL3 serves as an innovative platform set to redefine the approach towards health and wellness. Focused on integrating DePIN and DID alongside AI systems, the project is designed to create personalized user experiences while ensuring the safety and privacy of individuals' health data. With an impressive figure of over one million pre-registered users, the primary mission of WELL3 revolves around enhancing well-being through secure, data-driven health journeys. At its core, WELL3 employs advanced blockchain technologies to ensure that users have complete control over their personal information. This project not only addresses the challenges of data security and accessibility but also aspires to create a vibrant community connected by a shared commitment to better health. Key Features of WELL3: DePIN and DID: These technologies enable secure ownership and authentication of data, giving users full control over their information. AI Integration: Utilizing AI analytics, WELL3 offers personalized insights and solutions tailored to individual health needs. Community Engagement: Facilitates a supportive environment where users can connect, share experiences, and motivate each other toward healthier living. Creator of WELL3, $$WELL The identity of the creator of WELL3 remains unspecified in the available information. As the project progresses, further details may emerge, shedding light on the visionary minds behind this transformative initiative. Investors of WELL3, $$WELL WELL3 has garnered support from a myriad of influential investment entities, highlighting its credibility and potential in the health and wellness space. Notable investors include: Animoca Brands AWS Samsung The Spartan Group Blocore Fenbushi Capital Newman Group Soul Capital XY Finance Lumoz The backing from these established organizations demonstrates a strong belief in WELL3's mission, providing it with the necessary resources to innovate and expand its offerings. How Does WELL3, $$WELL Work? WELL3 operates by melding cutting-edge technologies in a multichain framework, ensuring a seamless and innovative user experience. Below are some factors that uniquely position WELL3 in the wellness market: 1. Secure Data Ownership With the integration of DePIN and DID, users can maintain complete control over their personal health information. This layer of security is paramount in today's digital age, where data breaches and unauthorized access are rampant. Through WELL3, data ownership is decentralised, enabling users to manage their information proactively. 2. Personalization through AI WELL3 implements AI-driven analytics to provide users with tailored health insights. By harnessing the power of AI, the platform can offer individualised recommendations and solutions, encouraging users to achieve their health goals more effectively. 3. Multichain Framework The WELL3 project is designed to work across multiple blockchain platforms, including Bitcoin, Ethereum, Polygon, Solana, Blast, and TON. This multichain capability ensures that users can interact with the platform seamlessly across different networks, enhancing accessibility and usability. 4. WELL Token Central to the WELL3 ecosystem is the WELL Token, which serves multiple functions including utility, governance, and rewards. The token allows for ecosystem participation, supports health data sharing, and incentivizes users based on their engagement with the platform. Timeline of WELL3, $$WELL The trajectory of WELL3 showcases significant milestones in its development, each contributing to the project's overall success. Here is a brief timeline of critical events in the history of WELL3: February 10, 2024: WELL3 launched its NFT project, quickly rising to prominence as the largest NFT collection on the opBNB chain with over 324,000 owners and reaching 8 million NFTs created by April 27, 2024. Public Sale: The project achieved a remarkable total value locked (TVL) of approximately 15,237.2 ETH within just seven days, indicating robust market interest and backing. WELL ID Launch: The platform saw over 900,000 users sign up for the WELL ID and its corresponding NFT Ring whitelist, marking a significant adoption phase within the ecosystem. Partnership Development: WELL3 established partnerships with leading entities including Animoca Brands, AWS, Samsung, and others to enhance its ecosystem and expand its reach. Transaction Volume: WELL3 has facilitated over $17 million in transactions, reflecting its growing utility and engagement within the health and wellness community. Key Points About WELL3, $$WELL As a progressive initiative shifting towards the wellness market, WELL3 has identified several vital elements that will contribute to its ongoing success. Here are some key takeaways to note: Tokenomics The $$WELL token has a maximum supply of 42 billion, with a significant 71% earmarked for community initiatives. This distribution strategy emphasises the project's commitment to its user base and long-term sustainability. Lock-Up Period To ensure stability within the ecosystem, tokens are released in batches over a 24-month lock-up period, promoting trust and confidence among users. Ecosystem Development WELL3's vision extends toward creating a comprehensive and sustainable ecosystem to encourage thriving community engagement, health-enhancing behaviors, and digital solutions that address the pressing needs of the wellness domain. Market Fit The wellness industry, valued at $5.6 trillion, presents a lucrative opportunity that WELL3 aims to tap into. With an anticipated annual growth rate of 5-10%, the project is ideally positioned amid a rising trend towards health-conscious living. Wearables Introducing the WELL3 Ring, a crypto-incentivized wearable, aligns with the growing demand for personalized health data. This device not only enhances user experience but also redefines what it means to be engaged with one’s health in the context of Web3. Conclusion WELL3 represents a significant advancement in the integration of blockchain technology within the health and wellness sector. By addressing crucial issues around data ownership, personalization, and community engagement, this innovative platform offers a forward-thinking solution to enhance individual well-being. With robust backing from notable investors and a commitment to pioneering technologies, WELL3 stands poised to make a lasting impact in the wellness landscape. For those seeking to navigate the complexities of health in the digital age, WELL3 is certainly one to watch as it continues to evolve and grow.

548 Total ViewsPublished 2024.07.14Updated 2024.12.03

What is $WELL

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of WELL (WELL) are presented below.

活动图片