See More

PancakeSwap DeFi DEX Details Patched Lottery Bug

2 mins
Updated by Kyle Baird
Join our Trading Community on Telegram

In Brief

  • Lottery bug discovered within PancakeSwap DEX.
  • Smart contract was fixed and no funds were stolen.
  • DEX TVL surges but CAKE prices cool off after a weekend high.
  • promo

A vulnerability in the PancakeSwap crypto lottery protocol has been fixed before any bad actors could exploit it. The developer team is now divulging all the details.

In a post mortem type article on March 29, the PancakeSwap team detailed a bug in its lottery smart contract. A whitehat hacker discovered the critical vulnerability before any funds were stolen.

Blockchain and smart contract security firm Immunefi, in cooperation with a whitehat known as “Thunder,” facilitated the patch.

Lottery Bug Patched

The post mortem elaborated on the vulnerability. It allowed a ‘multibuy’ function to purchase tickets while the lottery was still in the drawing phase.

“This meant that a user could see the lottery draw transaction, compute the winning lottery number, buy the right ticket during the draw, and frontrun with a high gas fee to win the lottery.”

It added that the block time is relatively short on Binance Smart Chain. So, computations for the winning ticket would need to be done quickly and would cost a very high gas fee.

At around $12 per CAKE and 20,000 CAKE per lottery, $240,000 per lottery could have been discreetly and repeatedly stolen. The team updated the smart contract to prevent compromised lottery draws in the future.

Every 12 hours the automated market maker runs a CAKE lottery which costs 1 CAKE per ticket. This gives the holder a random four-digit combination of numbers between 1 and 14. Participants must match all four numbers to win the pot.

PancakeSwap has hosted a million-dollar bug bounty with Immunefi, which launched on March 26.

DEX TVL and CAKE Price Update

PancakeSwap has experienced huge growth over the past month or so. At the same time, high gas fees render Uniswap impractical for those with smaller amounts to invest in DeFi.

According to crypto wallet provider Debank, PancakeSwap actually surpassed Uniswap in daily volumes briefly last week. DappRadar is reporting a total value locked for both DEXs at around $5.4 billion today.

PancakeSwap’s native token, CAKE, is trading for $16.97. This is a 4% gain from its daily open. It hit an all-time high of just under $20 on Feb. 20 and was close to tapping those levels again over this past weekend.

Top crypto projects in the US | April 2024

Trusted

Disclaimer

In adherence to the Trust Project guidelines, BeInCrypto is committed to unbiased, transparent reporting. This news article aims to provide accurate, timely information. However, readers are advised to verify facts independently and consult with a professional before making any decisions based on this content. Please note that our Terms and ConditionsPrivacy Policy, and Disclaimers have been updated.

profile.jpg
Martin Young
Martin Young is a seasoned cryptocurrency journalist and editor with over 7 years of experience covering the latest news and trends in the digital asset space. He is passionate about making complex blockchain, fintech, and macroeconomics concepts understandable for mainstream audiences.   Martin has been featured in top finance, technology, and crypto publications including BeInCrypto, CoinTelegraph, NewsBTC, FX Empire, and Asia Times. His articles provide an in-depth analysis of...
READ FULL BIO
Sponsored
Sponsored