Community Investigation

CashCowCoin’s $117K Reserve-Manipulation Exploit: The Profit Did Not Stay With the Attacker EOA

REPORT
REPORT

August 29, 2026

Executive Summary

On 27 August 2026, a single BNB Smart Chain transaction used two large WBNB funding legs to manipulate the CCC/WBNB pool and extract 165.47192825151242 WBNB in profit. SentinelTX reconstructed the transaction flow and identified an important attribution distinction: the transaction signer paid the gas, but the profit was routed through a second contract to a different externally owned account.

The evidence supports a reserve-manipulation exploit. It does not, by itself, identify the human operator.

Evidence Boundary

The primary evidence is the successful attack transaction 0x89d8050641019a5a75fa3dafb4f64fb153e4dd30c0f1f51d06a6cc206d3ead43, confirmed at block 118,384,061 on 27 August 2026 at 12:31:31 UTC. Public reporting describes a roughly $117,000 loss. Dollar values are therefore contextual; token amounts and transaction relationships below come from the on-chain reconstruction.

Transaction-Level Attack Sequence

The attack signer 0x7977…13c4 invoked a helper deployed the same day. That helper aggregated 833,662.974022 WBNB across two funding legs. It then donated WBNB to the CCC/WBNB pair and triggered a reserve update before repeatedly trading against a system whose executable pricing depended on the manipulated pool state.

Per confirmed cycle, 44,029.20 CCC moved to the burn address and 61,640.88 CCC returned to the pair. The loop was repeated 80 times. The mechanism matters more than the nominal flash-loan size: temporary liquidity only amplified a pricing dependency that trusted manipulable spot reserves inside one transaction.

Repayment and Profit Extraction

The first lender received exactly 416,831.487011 WBNB. The second contract received 416,996.958940 WBNB, including the surplus. One minute later, transaction 0x15be1604…acd97f moved the 165.471928 WBNB profit from that contract to 0xca8821…b72a9. Transaction 0xdaeada7c…8bf5 then unwrapped it into native BNB.

At the investigation cutoff, the profit recipient held 165.53941989 BNB. SentinelTX found no confirmed direct deposit from this profit path to a centralized exchange, bridge, or mixer. That creates a live monitoring window, not proof that the funds will remain stationary.

Address and Role Matrix

Address

Observed role

Assessment

0x7977…13c4

Attack transaction signer

Paid gas; did not receive the profit

0x7738…aeaf

Same-day helper contract

Aggregated funding and executed the sequence

0x1dbe…97c0

CCC/WBNB pair

Reserve state was distorted before Sync

0xf523…41c7

Victim sale/AMM contract

Executable pricing dependency requires code review

0xbabf…7a9f

Second funding/repayment contract

Forwarded extracted profit

0xca8821…b72a9

Profit recipient EOA

Unwrapped WBNB; funds stationary at cutoff

What the Chain Proves — and What It Does Not

The chain proves the transaction ordering, token transfers, repayments, profit amount, and immediate post-exploit destination. It also shows that the signer and the profit recipient were different addresses.

A shared gas source and a shared USDT source create a strong operational-cluster inference between relevant addresses, but they do not establish identity. The ultimate source of the second funding leg remains unresolved. The precise contract-level pricing formula and the relationship between two reported CCC contract identifiers also require separate code and deployment review.

Investigator Priorities

  • Monitor 0xca8821…b72a9 for first-hop movement, especially wrapping, bridging, or exchange deposits.
  • Trace the upstream provenance of the second 416,831.487011 WBNB funding leg.
  • Review the victim contract for direct or indirect reliance on pair reserves during executable pricing.
  • Preserve the funding, attack, payout, and unwrap transactions as one evidence package.

Conclusion

This was not simply a “large flash loan” event. The decisive control failure was allowing a manipulable pool state to influence executable pricing within the same transaction. The clearest recovery lead is the profit-recipient EOA, where the extracted value was still visible and had not entered a confirmed obfuscation or off-ramp service at the cutoff.

Sources: SentinelTX on-chain investigation; Defimon Alerts; BitBase incident report.

post_like_sub0
post_total_comment_sub0

2 reads

0/500 bytes