A damaged PancakeSwap pool releases USDT through a pipe while two hooded figures stand behind it and a broken lock exposes liquidity risks.
Image by CryptoSlate

Locked liquidity did not stop this $14 million crypto pool drain

Bitquery traced 79AU’s drain to token permissions that bypassed burned LP receipts, with residual rights documented on Oct. 8.

Quick Take

  1. Bitquery traced a $14.35 million USDT drain from 79AU’s pool on October 7 despite burned liquidity receipts.
  2. Burned LP receipts restricted redemption, while a separate token permission supplied 79AU that could be sold back for USDT.
  3. Two addresses retained pull rights in Bitquery’s October 8 snapshot; read-only tests moved no funds.

The PancakeSwap pool for 79AU, 79thVault’s token, lost $14.35 million in USDT on Oct. 7 through two selling wallets, according to a Bitquery investigation published Oct. 8.

Bitquery found that 79% of the pool’s liquidity-provider receipts had been burned. But a permission inside 79AU let tokens leave the pool without payment. Those tokens were then sold back for USDT, bypassing the need to redeem a liquidity receipt.

Related Reading

Crypto hackers exploit third-party Aave tool to steal 114 ETH

PancakeSwap’s V2 documentation describes LP tokens as receipts representing a provider’s share of a pool. They are separate from the two assets traders exchange inside it.

The exchange’s liquidity guide describes ordinary redemption: a provider selects a share to remove and receives both paired tokens. Sending receipts to an inaccessible address prevents their redemption. It does not disable swaps, since trading exchanges the underlying assets without cashing in a liquidity position.

In PancakeSwap’s archived pair contract, separate operations handle LP redemption, swaps and updating recorded reserves to match token balances. The swap operation checks token input without consuming LP receipts. The reserve-update operation reads balances from the underlying token contracts. Burning LP receipts does not rewrite those contracts’ balance rules or revoke a privileged address’s token permissions.

Related Reading

Base’s Cobalt upgrade adds another rule to affect token balances

What remained exposed

At 12:53 UTC on Oct. 8, Bitquery identified two pull-authorized addresses: the deployer and a newly authorized wallet. Read-only simulations from either allowed removal of about 95% of the pool’s remaining 79AU. The read-only tests moved no funds.

The same snapshot showed one wallet holding the unburned 21% of LP receipts, with ordinary redemption rights over that share.

Related Reading

Cardano’s Splash fix patches the exploit, but leaves 2.4M ADA missing and holders trapped

Establishing whether 79AU’s reported exposure has ended requires a fresh check of that transfer permission.

Article context

Mentioned in this article

Related Asset Tether USDT · Stablecoin Related Company PancakeSwap Company profile