CryptoReal
CASE FILE — May 29, 2021

Flash-Loan Share Price Manipulation Drains $6.3M From Belt on BSC

A flash-loan-driven manipulation of share valuation cost Belt Finance $6.3 million, adding another entry to the string of similar exploits that hit BSC protocols during this period. The attack was somewhat more elaborate than earlier BSC incidents, but relied on the same underlying weaknesses seen throughout the season.

Attack sequence

  1. The attacker took out eight flash loans totaling $385M in BUSD from PancakeSwap.
  2. 10M BUSD was deposited into the bEllipsisBUSD strategy — this step applied only to the first transaction, when it was the "Most Undersubscribed Strategy."
  3. 187M BUSD was deposited into the bVenusBUSD strategy, at the time also the "Most Undersubscribed Strategy."
  4. 190M BUSD was swapped for 169M USDT via Ellipsis.
  5. Additional BUSD was withdrawn from the bVenusBUSD strategy, by then the "Most Oversubscribed Strategy."
  6. The 169M USDT was swapped back to 189M BUSD via Ellipsis.
  7. BUSD was deposited again into the bVenusBUSD strategy (once more the "Most Undersubscribed Strategy").

Steps 4 through 7 were repeated seven times in total before the attacker repaid the flash loans and withdrew the profit.

Sums referenced in this case file

Notably, the attacker was not the only party to benefit — EPS liquidity providers and stakers also picked up a share of the proceeds from this incident.

Credit for the analysis goes to FrankResearcher and Mudit__Gupta.

Echoes of a past exploit

Observers quickly drew parallels to the Harvest Finance hack covered previously, where a similar sequence of events allowed an attacker to extract more than $25 million. Adding an ironic twist, Belt had been publicly touting a new partnership with Harvest Finance just two days before this exploit occurred. Some in the community questioned whether the source of the attack might trace back to an external project, pointing to what they described as uninformed responses from Belt's developers.

Binance also commented on the situation, though the broader run of BSC exploits showed no signs of slowing.

BSCBelt
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.