📢 Gate Square Exclusive: #PUBLIC Creative Contest# Is Now Live!
Join Gate Launchpool Round 297 — PublicAI (PUBLIC) and share your post on Gate Square for a chance to win from a 4,000 $PUBLIC prize pool
🎨 Event Period
Aug 18, 2025, 10:00 – Aug 22, 2025, 16:00 (UTC)
📌 How to Participate
Post original content on Gate Square related to PublicAI (PUBLIC) or the ongoing Launchpool event
Content must be at least 100 words (analysis, tutorials, creative graphics, reviews, etc.)
Add hashtag: #PUBLIC Creative Contest#
Include screenshots of your Launchpool participation (e.g., staking record, reward
Cellframe Network suffered a liquidity migration attack, with hackers profiting $76,000.
Analysis of the Liquidity Migration Attack Incident on Cellframe Network
On June 1, 2023, at 10:07:55 (UTC+8), Cellframe Network was hacked on a certain smart chain due to a token quantity calculation issue during the Liquidity migration process. This attack resulted in the hackers profiting approximately $76,112.
Event Analysis
The attacker exploited a computational vulnerability in liquidity migration. The attack process is as follows:
The migration process includes:
Due to the scarcity of Old Cell tokens in the old pool, the number of a certain chain's native tokens obtained when removing liquidity increases, while the number of Old Cell tokens decreases. This causes users to only need to add a small amount of a certain chain's native tokens and New Cell tokens to acquire liquidity, while the excess certain chain's native tokens and Old Cell tokens are returned to the users.
Summary and Suggestions
When conducting liquidity migration, it is essential to comprehensively consider the changes in the quantities of the two tokens in the old and new pools, as well as the current token prices. Calculating directly based on the quantities of the two tokens in the trading pair is prone to manipulation.
In addition, the project team should conduct a comprehensive security audit before the code goes live to prevent similar vulnerabilities from occurring. This incident underscores the importance of thorough security checks in Web3 projects, especially when involving complex financial operations.