Live Prices
DeFi

PancakeSwap 79AU Pool Drained of $14.35 Million Despite Locked Liquidity

TheCryptoDesk Editorial · 2m read
PancakeSwap 79AU Pool Drained of $14.35 Million Despite Locked Liquidity

A decentralized finance liquidity pool for 79thVault's native token 79AU on PancakeSwap was drained of $14.35 million in USDT on Oct. 7, despite 79% of the pool's liquidity provider (LP) tokens being burned to signal locked liquidity.

According to an investigation published on Oct. 8 by blockchain analysis firm Bitquery—whose analytical tools were previously featured when a Bitquery audit revealed fake holder growth patterns—the attackers bypassed traditional liquidity locks by leveraging a privileged permission baked directly into the custom 79AU token contract.

How the 79AU Pool Was Exploited

The exploit executed through two selling wallets that extracted 79AU tokens directly from the PancakeSwap pool without providing payment. These extracted tokens were subsequently swapped back into the liquidity pool for USDT, bypassing the standard requirement to redeem LP receipts.

In PancakeSwap V2 architecture, LP tokens serve as receipts representing a provider's proportional share of a pool. While sending LP receipts to an unspendable burn address prevents liquidity withdrawal via standard redemption, it does not stop regular swap functions or alter smart contract permissions. PancakeSwap's underlying pair contract handles LP redemptions, token swaps, and reserve updates as separate operations, relying on token balances reported directly by the underlying smart contract.

Key facts of the incident include:

  • $14.35 million in USDT was siphoned from the 79AU liquidity pool on Oct. 7.
  • 79% of the pool's total LP receipts had been burned prior to the drain.
  • Privileged transfer permissions inside the 79AU smart contract enabled direct token extraction without redeeming LP receipts.
  • Simulations conducted at 12:53 UTC on Oct. 8 showed 95% of remaining 79AU pool reserves remained vulnerable.

Bitquery Audit Identifies Remaining Vulnerabilities

At 12:53 UTC on Oct. 8, Bitquery identified two pull-authorized addresses—the contract deployer and a newly authorized wallet—capable of draining the pool further. Read-only simulations demonstrated that these two addresses could remove approximately 95% of the pool's remaining 79AU balance, though no funds were moved during the test simulations.

Additionally, Bitquery noted that a single wallet held the remaining 21% of unburned LP receipts, retaining standard redemption rights over that portion of the pool's reserves.

Why It Matters

This incident underscores a critical flaw in relying solely on LP token burns as a trust signal for decentralized trading pairs. While burning LP receipts locks standard liquidity redemptions, it provides zero protection against malicious or compromised functions embedded directly inside custom token contracts. Investors and audit teams must look beyond surface-level liquidity locks and inspect underlying smart contract permissions to ensure administrative bypasses are impossible.

Terms in this article

Read next