Une « autodestruction » soigneusement conçue : Analyse de l'attaque PGNLZ

marsbitPublished on 2026-01-28Last updated on 2026-01-28

Abstract

Une attaque soigneusement planifiée contre le projet PGNLZ sur BNB Smart Chain a été détectée le 27 janvier 2026, causant une perte d’environ 100 000 USD. L’attaquant a utilisé un flash loan de 1 059 BTCB via Moolah Protocol, puis les a déposés comme garantie sur Venus Protocol pour emprunter 30 000 000 USDT. Ensuite, l’attaquant a échangé 23 337 952 USDT contre 982 506 PGNLZ sur PancakeSwap, mais a immédiatement brûlé ces tokens (en les envoyant à l’adresse 0xdead). Cette action a drastiquement réduit l’offre de PGNLZ dans le pool, faisant monter son prix de 0,1 USDT à 5 528 USDT. L’attaquant a ensuite exploité la fonction de taxe de vente (Fee-On Transfer) du token, qui déclenchait un mécanisme de brûlage (_executeBurnFromLP) supprimant presque entièrement les tokens restants du pool. Le prix a alors été artificiellement gonflé à 234 385 300 000 000 USDT par PGNLZ, permettant à l’attaquant de vider le pool et de réaliser un profit après remboursement du prêt. La cause principale de cette vulnérabilité est un modèle économique déflationniste mal sécurisé, sans vérification adéquate lors des opérations de taxation ou de brûlage. Il est recommandé aux projets de bien valider leurs mécanismes économiques et de réaliser des audits croisés avant le déploiement.

Contexte

Le 27 janvier 2026, nous avons détecté une attaque sur le projet PGNLZ sur le BNB Smart Chain :

https://bscscan.com/tx/0xa7488ff4d6a85bf19994748837713c710650378383530ae709aec628023cd7cc

Après une analyse détaillée, l'attaquant a lancé une attaque soutenue contre le projet PGNLZ le 27 janvier 2026, causant une perte d'environ 100 000 USD.

Analyse de l'attaque et de l'événement

L'attaquant a d'abord emprunté 1 059 BTCB via un flash loan auprès de Moolah Protocol,

Puis, il a déposé ces 1 059 BTCB en collatéral sur Venus Protocol pour emprunter 30 000 000 USDT.

Ensuite, l'attaquant a appelé la fonction `swapTokensForExactTokens` sur PancakeSwap, utilisant 23 337 952 USDT pour échanger contre 982 506 PGNLZ, mais a ensuite brûlé ces PGNLZ (en les envoyant à l'adresse 0xdead).

Avant l'échange, le pool PancakeSwap contenait 100 901 USDT et 982 506 PGNLZ, le prix du PGNLZ était donc de 1 PGNLZ = 0,1 USDT. Après l'échange, le pool PancakeSwap contenait 23 438 853 USDT et 4 240 PGNLZ, le prix du PGNLZ est alors passé à 1 PGNLZ = 5 528 USDT.

Par la suite, l'attaquant a appelé la fonction `swapExactTokensForTokensSupportingFeeOnTransferTokens`, une fonction conçue pour prendre en charge les tokens avec frais de transfert (Fee-On Transfer Token). PGNLZ utilise `_update` pour gérer les frais de transaction, la chaîne d'appel spécifique étant : `transferFrom` -> `_spendAllowance` -> `_transfer` -> `_update`.

Comme il s'agissait d'une vente (sell), la fonction `_handleSellTax` a été appelée.

Examinons comment `_executeBurnFromLP` est implémentée,

On peut voir que `_executeBurnFromLP` utilise `_update` pour brûler la quantité de PGNLZ définie par `pendingBurnFromLP`. Le bloc précédent indiquait que `pendingBurnFromLP` était de 4 240 113 074 578 781 194 669.

Après le burn, il ne restait plus que 0,00000001 PGNLZ dans le pool de liquidité (LP Pool), le prix est alors passé à 1 PGNLZ = 234 385 300 000 000 USDT, soit une multiplication par 40 milliards.

Enfin, l'attaquant a vidé le LP Pool, a remboursé le flash loan, et a réalisé un profit de 100 000 USDT.

Conclusion

La cause de cette vulnérabilité réside dans le modèle économique déflationniste, qui ne valide pas les frais prélevés ou la combustion du pool de liquidité. Cela a permis à l'attaquant de manipuler le prix du token en exploitant ses caractéristiques déflationnistes. Il est recommandé aux projets de valider minutieusement la conception de leur modèle économique et la logique d'exécution du code, et de privilégier un audit croisé par plusieurs sociétés d'audit avant le déploiement du contrat.

Related Questions

QQuel est la cause principale de l'attaque contre le projet PGNLZ sur BNB Smart Chain ?

ALa cause principale est le modèle économique déflationniste du token, avec une vulnérabilité dans la vérification lors des frais de transaction ou de la destruction des tokens du pool de liquidité, permettant à l'attaquant de manipuler le prix.

QComment l'attaquant a-t-il initialement obtenu les fonds pour lancer l'attaque ?

AL'attaquant a obtenu un flash loan de 1 059 BTCB auprès de Moolah Protocol, qu'il a ensuite utilisé comme garantie pour emprunter 30 000 000 USDT sur Venus Protocol.

QQuelle action spécifique a provoqué l'augmentation massive du prix du PGNLZ ?

AL'attaquant a brûlé une énorme quantité de PGNLZ (4 240 113 074 578 781 194 669 tokens) via la fonction _executeBurnFromLP, ne laissant que 0,00000001 PGNLZ dans le pool, ce qui a fait monter le prix de 40 milliards de fois.

QQuel était le prix du PGNLZ avant et après la manipulation par l'attaquant ?

AAvant la manipulation : 1 PGNLZ = 0,1 USDT. Après la manipulation : 1 PGNLZ = 234 385 300 000 000 USDT.

QQuelle est la recommandation principale pour éviter ce type d'attaque à l'avenir ?

AIl est recommandé de valider soigneusement le modèle économique et la logique du code, et de faire auditer le contrat par plusieurs sociétés d'audit différentes avant son déploiement.

Related Reads

DeepSeek Announces Permanent Price Cut, But Liang Wenfeng Is Not Trying to Be a "Cyber Bodhisattva"

DeepSeek has announced a permanent 75% discount on its V4-Pro API, significantly reducing its token prices. This move stands out as a major industry-wide price cut while competitors like Anthropic, OpenAI, and Google have been quietly raising theirs. The article contrasts this strategy with the broader trend of AI becoming more expensive, citing examples of companies like Microsoft and Uber struggling with high token costs as usage soars. While CEO Liang Wenfeng is hailed by some as a "Cyber Bodhisattva" for this普惠 approach, the article argues this is a strategic business choice, not mere altruism. DeepSeek's ability to maintain low prices is attributed to several structural advantages: lower-cost AI talent in China, the impending use of domestic昇腾 hardware for further cost reductions, and, most critically, access to China's cheaper and more abundant energy infrastructure, which drastically reduces the electricity costs dominating AI operations. The analysis suggests that for many commercial applications, a "good enough" model that is radically cheaper (e.g., 1% to 11% of GPT-5.5's cost) is more valuable than the absolute top-tier model. This allows for vastly more experimentation and iteration within a budget. Therefore, as AI generally becomes more expensive, DeepSeek's cost-competitiveness—rooted in China's energy and talent advantages—becomes its core strategic value and differentiator in the global market.

marsbit10h ago

DeepSeek Announces Permanent Price Cut, But Liang Wenfeng Is Not Trying to Be a "Cyber Bodhisattva"

marsbit10h ago

The Veil of Mythos Becomes Anthropic's Lever to Move Trillions

The article discusses Anthropic's reported upcoming $30 billion funding round, which would value the company at over $900 billion. It analyzes how the company has leveraged strategic narratives around its unreleased "Mythos" model, rather than just its publicly available products, to drive this massive valuation. Key points include Google's surprising $40 billion investment in a competitor, suggesting it is buying strategic positioning. Anthropic's "Glasswing" cybersecurity project and the unreleased Mythos model are portrayed not through direct proof, but through carefully crafted narratives of being "too powerful for public release," creating an aura of exclusive, high-level capability. This is bolstered by reports of the White House and NSA seeking access to Claude/Mythos despite previous security concerns, implying indispensable technology. Furthermore, Anthropic's reported rapid revenue growth—from a $1 billion annual run-rate in late 2024 to over $30 billion by April 2026, largely driven by enterprise API and Claude Code—provides a financial story for investors. The article concludes that Anthropic's core business model is effectively converting unverifiable technical potential, government interest, and future revenue projections into a compelling narrative that secures immense capital, using the actions of wealthy investors and powerful institutions as the ultimate validation of its worth.

marsbit12h ago

The Veil of Mythos Becomes Anthropic's Lever to Move Trillions

marsbit12h ago

Trading

Spot
Futures

Hot Articles

How to Buy WELL

Welcome to HTX.com! We've made purchasing Moonwell Artemis (WELL) simple and convenient. Follow our step-by-step guide to embark on your crypto journey.Step 1: Create Your HTX AccountUse your email or phone number to sign up for a free account on HTX. Experience a hassle-free registration journey and unlock all features.Get My AccountStep 2: Go to Buy Crypto and Choose Your Payment MethodCredit/Debit Card: Use your Visa or Mastercard to buy Moonwell Artemis (WELL) instantly.Balance: Use funds from your HTX account balance to trade seamlessly.Third Parties: We've added popular payment methods such as Google Pay and Apple Pay to enhance convenience.P2P: Trade directly with other users on HTX.Over-the-Counter (OTC): We offer tailor-made services and competitive exchange rates for traders.Step 3: Store Your Moonwell Artemis (WELL)After purchasing your Moonwell Artemis (WELL), store it in your HTX account. Alternatively, you can send it elsewhere via blockchain transfer or use it to trade other cryptocurrencies.Step 4: Trade Moonwell Artemis (WELL)Easily trade Moonwell Artemis (WELL) on HTX's spot market. Simply access your account, select your trading pair, execute your trades, and monitor in real-time. We offer a user-friendly experience for both beginners and seasoned traders.

2.2k Total ViewsPublished 2024.03.29Updated 2025.03.21

How to Buy WELL

What is $WELL

WELL3, $$WELL: Revolutionizing Health and Wellness with DePIN and AI Introduction In the rapidly evolving landscape of digital technology, the health and wellness sector stands at the forefront of innovation, striving to enhance patient care and promote healthier lifestyles. A groundbreaking player in this domain is WELL3, a pioneering Web3 project that seeks to revolutionize how individuals engage with their health. By leveraging technologies such as Decentralized Physical Infrastructure Network (DePIN), Decentralized Identity (DID), and Artificial Intelligence (AI), WELL3 aims to foster secure, data-empowered health journeys. This comprehensive article delves deep into the core aspects of WELL3, $$WELL, exploring its functionalities, creators, investors, and unique features. What is WELL3, $$WELL? WELL3 serves as an innovative platform set to redefine the approach towards health and wellness. Focused on integrating DePIN and DID alongside AI systems, the project is designed to create personalized user experiences while ensuring the safety and privacy of individuals' health data. With an impressive figure of over one million pre-registered users, the primary mission of WELL3 revolves around enhancing well-being through secure, data-driven health journeys. At its core, WELL3 employs advanced blockchain technologies to ensure that users have complete control over their personal information. This project not only addresses the challenges of data security and accessibility but also aspires to create a vibrant community connected by a shared commitment to better health. Key Features of WELL3: DePIN and DID: These technologies enable secure ownership and authentication of data, giving users full control over their information. AI Integration: Utilizing AI analytics, WELL3 offers personalized insights and solutions tailored to individual health needs. Community Engagement: Facilitates a supportive environment where users can connect, share experiences, and motivate each other toward healthier living. Creator of WELL3, $$WELL The identity of the creator of WELL3 remains unspecified in the available information. As the project progresses, further details may emerge, shedding light on the visionary minds behind this transformative initiative. Investors of WELL3, $$WELL WELL3 has garnered support from a myriad of influential investment entities, highlighting its credibility and potential in the health and wellness space. Notable investors include: Animoca Brands AWS Samsung The Spartan Group Blocore Fenbushi Capital Newman Group Soul Capital XY Finance Lumoz The backing from these established organizations demonstrates a strong belief in WELL3's mission, providing it with the necessary resources to innovate and expand its offerings. How Does WELL3, $$WELL Work? WELL3 operates by melding cutting-edge technologies in a multichain framework, ensuring a seamless and innovative user experience. Below are some factors that uniquely position WELL3 in the wellness market: 1. Secure Data Ownership With the integration of DePIN and DID, users can maintain complete control over their personal health information. This layer of security is paramount in today's digital age, where data breaches and unauthorized access are rampant. Through WELL3, data ownership is decentralised, enabling users to manage their information proactively. 2. Personalization through AI WELL3 implements AI-driven analytics to provide users with tailored health insights. By harnessing the power of AI, the platform can offer individualised recommendations and solutions, encouraging users to achieve their health goals more effectively. 3. Multichain Framework The WELL3 project is designed to work across multiple blockchain platforms, including Bitcoin, Ethereum, Polygon, Solana, Blast, and TON. This multichain capability ensures that users can interact with the platform seamlessly across different networks, enhancing accessibility and usability. 4. WELL Token Central to the WELL3 ecosystem is the WELL Token, which serves multiple functions including utility, governance, and rewards. The token allows for ecosystem participation, supports health data sharing, and incentivizes users based on their engagement with the platform. Timeline of WELL3, $$WELL The trajectory of WELL3 showcases significant milestones in its development, each contributing to the project's overall success. Here is a brief timeline of critical events in the history of WELL3: February 10, 2024: WELL3 launched its NFT project, quickly rising to prominence as the largest NFT collection on the opBNB chain with over 324,000 owners and reaching 8 million NFTs created by April 27, 2024. Public Sale: The project achieved a remarkable total value locked (TVL) of approximately 15,237.2 ETH within just seven days, indicating robust market interest and backing. WELL ID Launch: The platform saw over 900,000 users sign up for the WELL ID and its corresponding NFT Ring whitelist, marking a significant adoption phase within the ecosystem. Partnership Development: WELL3 established partnerships with leading entities including Animoca Brands, AWS, Samsung, and others to enhance its ecosystem and expand its reach. Transaction Volume: WELL3 has facilitated over $17 million in transactions, reflecting its growing utility and engagement within the health and wellness community. Key Points About WELL3, $$WELL As a progressive initiative shifting towards the wellness market, WELL3 has identified several vital elements that will contribute to its ongoing success. Here are some key takeaways to note: Tokenomics The $$WELL token has a maximum supply of 42 billion, with a significant 71% earmarked for community initiatives. This distribution strategy emphasises the project's commitment to its user base and long-term sustainability. Lock-Up Period To ensure stability within the ecosystem, tokens are released in batches over a 24-month lock-up period, promoting trust and confidence among users. Ecosystem Development WELL3's vision extends toward creating a comprehensive and sustainable ecosystem to encourage thriving community engagement, health-enhancing behaviors, and digital solutions that address the pressing needs of the wellness domain. Market Fit The wellness industry, valued at $5.6 trillion, presents a lucrative opportunity that WELL3 aims to tap into. With an anticipated annual growth rate of 5-10%, the project is ideally positioned amid a rising trend towards health-conscious living. Wearables Introducing the WELL3 Ring, a crypto-incentivized wearable, aligns with the growing demand for personalized health data. This device not only enhances user experience but also redefines what it means to be engaged with one’s health in the context of Web3. Conclusion WELL3 represents a significant advancement in the integration of blockchain technology within the health and wellness sector. By addressing crucial issues around data ownership, personalization, and community engagement, this innovative platform offers a forward-thinking solution to enhance individual well-being. With robust backing from notable investors and a commitment to pioneering technologies, WELL3 stands poised to make a lasting impact in the wellness landscape. For those seeking to navigate the complexities of health in the digital age, WELL3 is certainly one to watch as it continues to evolve and grow.

548 Total ViewsPublished 2024.07.14Updated 2024.12.03

What is $WELL

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of WELL (WELL) are presented below.

活动图片