<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Caterpillar_Token_Flash_Loan_Smart_Contract_Drain</id>
	<title>Caterpillar Token Flash Loan Smart Contract Drain - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Caterpillar_Token_Flash_Loan_Smart_Contract_Drain"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Caterpillar_Token_Flash_Loan_Smart_Contract_Drain&amp;action=history"/>
	<updated>2026-06-20T21:48:08Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Caterpillar_Token_Flash_Loan_Smart_Contract_Drain&amp;diff=6225&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/caterpillartokenflashloansmartcontractdrain.php}} {{Unattributed Sources}}  Caterpillar TokenCaterpillar Token (CUT) runs through a smart contract on the Binance Smart Chain, which was first launched in July 2024. The project does not appear to have a website or other online presence. There is an account referenced for CUT2024CUT, however there is no ev...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Caterpillar_Token_Flash_Loan_Smart_Contract_Drain&amp;diff=6225&amp;oldid=prev"/>
		<updated>2024-10-17T00:53:31Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/caterpillartokenflashloansmartcontractdrain.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Binancesecurity.jpg&quot; title=&quot;File:Binancesecurity.jpg&quot;&gt;thumb|Caterpillar Token&lt;/a&gt;Caterpillar Token (CUT) runs through a smart contract on the Binance Smart Chain, which was first launched in July 2024. The project does not appear to have a website or other online presence. There is an account referenced for CUT2024CUT, however there is no ev...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study With About|source=https://www.quadrigainitiative.com/casestudy/caterpillartokenflashloansmartcontractdrain.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Binancesecurity.jpg|thumb|Caterpillar Token]]Caterpillar Token (CUT) runs through a smart contract on the Binance Smart Chain, which was first launched in July 2024. The project does not appear to have a website or other online presence. There is an account referenced for CUT2024CUT, however there is no evidence that this Twitter account ever existed. On September 10th, the smart contract was exploited via a Flash loan, allowing the exploiter to profit by a total of $1.4m USD. There is no evidence of any team response, investigation, or attempt to recover funds.&amp;lt;ref name=&amp;quot;bscscan-16142&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;thestreet-16143&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;coinstatsapp-16144&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cryptopolitan-16145&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;icoholder-16146&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;coinmarketcap-16147&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;coinpedia-16148&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;coinmarketcap-16149&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;bscscan-16150&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;dexscreener-16151&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;geckoterminal-16152&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;coinmarketcap-16153&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;verichainsblog-16154&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;certikcntwitter-16155&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;tenarmoralerttwitter-16156&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;0xcommitauditstwitter-16157&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;metatrustalerttwitter-16158&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;exvulsectwitter-16159&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;linkedin-16160&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;newsletter-16161&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;coinlive-16162&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;halborn-16163&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;certik-16164&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About Caterpillar Token ==&lt;br /&gt;
Caterpillar Token (CUT) runs through a smart contract on the Binance Smart Chain, which was first launched in July 2024.&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
This sections is included if a case involved deception or information that was unknown at the time. Examples include:&lt;br /&gt;
&lt;br /&gt;
* When the service was actually started (if different than the &amp;quot;official story&amp;quot;).&lt;br /&gt;
* Who actually ran a service and their own personal history.&lt;br /&gt;
* How the service was structured behind the scenes. (For example, there was no &amp;quot;trading bot&amp;quot;.)&lt;br /&gt;
* Details of what audits reported and how vulnerabilities were missed during auditing.&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
&amp;quot;On September 10th, 2024, Caterpillar Coin ($CUT) was hit by a flashloan attack, resulting in a loss of $1.4 million USD.&amp;quot;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - Caterpillar Token Flash Loan Smart Contract Drain&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|July 26th, 2024 4:14:56 AM MDT&lt;br /&gt;
|Caterpillar Coin Launched&lt;br /&gt;
|The smart contract for Caterpillar Coin is first created on the Binance Smart Chain.&lt;br /&gt;
|-&lt;br /&gt;
|September 10th, 2024 6:40:52 AM MDT&lt;br /&gt;
|Blockchain Exploit Transaction&lt;br /&gt;
|The timestamp of the transaction on the Binance Smart Chain which is credited as the exploit.&lt;br /&gt;
|-&lt;br /&gt;
|September 10th, 2024 4:00:00 PM MDT&lt;br /&gt;
|CertiK Exploit Analysis&lt;br /&gt;
|CertiK publishes an analysis of the exploit...&lt;br /&gt;
|-&lt;br /&gt;
|September 13th, 2024 12:51:03 PM MDT&lt;br /&gt;
|Coinpedia Weekly Report&lt;br /&gt;
|Coinpedia publishes a weekly report which includes the Caterpillar Coin hack.&lt;br /&gt;
|-&lt;br /&gt;
|September 13th, 2024 12:51:04 PM MDT&lt;br /&gt;
|Coinlive Article Title Mention&lt;br /&gt;
|The Caterpillar Coin incident is mentioned in the title for a Coinlive article, however there is no mention in the body of the article.&lt;br /&gt;
|-&lt;br /&gt;
|September 14th, 2024 2:36:04 AM MDT&lt;br /&gt;
|Verichains Blog Analysis&lt;br /&gt;
|Web3 security firm Verichains publishes an analysis of the incident/exploit on their blog.&lt;br /&gt;
|-&lt;br /&gt;
|September 16th, 2024 1:39:05 AM MDT&lt;br /&gt;
|Shashank Medium Analysis Post&lt;br /&gt;
|Shashank from SolidityScan posted an article on Medium which walked through the Caterpillar Coin exploit in some level of detail.&lt;br /&gt;
|-&lt;br /&gt;
|September 17th, 2024 12:36:00 AM MDT&lt;br /&gt;
|PandaLy Weekly Report Inclusion&lt;br /&gt;
|PandaLy includes the incident in their weekly report recap.&lt;br /&gt;
|-&lt;br /&gt;
|September 17th, 2024 4:27:07 AM MDT&lt;br /&gt;
|Yogendra Singh Diwan Posts&lt;br /&gt;
|A researcher named Yogendra Singh Diwan posts an article including an analysis of the incident on LinkedIn. While this article includes a logo for a CUT token, this logo is for an unrelated Carbon Utility Token project.&lt;br /&gt;
|-&lt;br /&gt;
|September 17th, 2024 11:12:02 AM MDT&lt;br /&gt;
|Blockthreat Week 37&lt;br /&gt;
|The incident is included as premium content inside the Blockthreat Week 37 news article.&lt;br /&gt;
|-&lt;br /&gt;
|October 3rd, 2024 3:00:33 AM MDT&lt;br /&gt;
|Halborn Article Inclusion&lt;br /&gt;
|The Caterpillar coin incident is included in one paragraph of a &amp;quot;Month In Review&amp;quot; summary of hacks which happened in the month of September, published by Halborn.&lt;br /&gt;
|-&lt;br /&gt;
|October 6th, 2024 5:26:00 PM MDT&lt;br /&gt;
|CryptoPolitan Article Mention&lt;br /&gt;
|The incident is mentioned briefly in an article written by Cryptopolitan about how much hacks have increased in September. This is reposted by CoinStats.&lt;br /&gt;
|-&lt;br /&gt;
|October 7th, 2024 11:26:53 AM MDT&lt;br /&gt;
|Brief Mention By The Street&lt;br /&gt;
|The Street shares a brief mention of the Caterpillar Coin flash loan hack in their &amp;quot;Technical Weaknesses in Smart Contracts Merit Targeted Security Solutions&amp;quot; article.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
&amp;quot;Caterpillar Coin suffered a flashloan attack resulting in a loss of ~$1.4M and causing a 99% slippage on the token. The attack exploited vulnerabilities in the &amp;quot;price protection mechanisms&amp;quot;, which led to the manipulation of token reserves and rewards.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;The attack appears to have followed a straightforward pattern: the attacker used a flash loan to borrow USDT from the USDT-WBNB pair, then ran a loop to create several contracts with the main attack logic running in the constructor. Before creating each contract, the exploiter transferred a large amount of USDT for the logic in the constructor to utilize.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;1. The attacker took out a 4.5 million USDT flashloan, swapped some for $CUT tokens, and added liquidity to the USDT-CUT pool.&lt;br /&gt;
2. Due to a flaw in the reward calculation process, the attacker was able to manipulate the token's reserves, significantly increasing their rewards.&lt;br /&gt;
3. By repeating this process, the attacker drained the liquidity pool, repaid the loan, and walked away with around $1.4M USD in profits.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
The calculation is vulnerable to price manipulation and the exploiter abused this in order to gain extra $CUT tokens, sold them and gained ~$1.4m from the BUSD-CUT pancake pair.&lt;br /&gt;
&lt;br /&gt;
The total amount lost has been estimated at $1,400,000 USD.&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed?&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
The calculation is vulnerable to price manipulation and the exploiter abused this in order to gain extra $CUT tokens, sold them and gained ~$1.4m from the BUSD-CUT pancake pair.&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
There do not appear to have been any funds recovered in this case.&lt;br /&gt;
&lt;br /&gt;
What funds were recovered? What funds were reimbursed for those affected users?&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
What parts of this case are still remaining to be concluded?&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;bscscan-16142&amp;quot;&amp;gt;[https://bscscan.com/tx/0x2c123d08ca3d50c4b875c0b5de1b5c85d0bf9979dffbf87c48526e3a67396827 BNB Smart Chain Transaction Hash (Txhash) Details | BscScan] (Accessed Oct 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;thestreet-16143&amp;quot;&amp;gt;[https://www.thestreet.com/crypto/innovation/technical-weaknesses-in-smart-contracts-merit-targeted-security-solutions- https://www.thestreet.com/crypto/innovation/technical-weaknesses-in-smart-contracts-merit-targeted-security-solutions-] (Accessed Oct 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;coinstatsapp-16144&amp;quot;&amp;gt;[https://coinstats.app/news/0219d649ce2ab9ff93ef70bdd77fb261c31b6bc0ed9270b5e4647eb12486d61c_Crypto-hacks-explode-8x-in-just-one-month%E2%80%94%24116M-stolen-in-September-alone/ CoinStats - Crypto hacks explode 8x in just one month—$11...] (Accessed Oct 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;cryptopolitan-16145&amp;quot;&amp;gt;[https://www.cryptopolitan.com/crypto-hacks-rise-116m-stolen-in-september/ https://www.cryptopolitan.com/crypto-hacks-rise-116m-stolen-in-september/] (Accessed Oct 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;icoholder-16146&amp;quot;&amp;gt;[https://icoholder.com/en/news/crypto-hacks-surge-in-september-2024-over-120-million-lost Crypto Hacks Surge in September 2024: Over $120 Million Lost] (Accessed Oct 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;coinmarketcap-16147&amp;quot;&amp;gt;[https://coinmarketcap.com/community/articles/66e48a789c6f076f3ed41ad8/ Coinpedia Fintech News: Guest Post by CoinPedia News | CoinMarketCap] (Accessed Oct 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;coinpedia-16148&amp;quot;&amp;gt;[https://coinpedia.org/news/crypto-hack-weekly-report-indodax-heist-caterpillar-coin-collapse-and-apples-deepfake-incident/ Crypto Hack Weekly Report: Indodax Heist, Caterpillar Coin Collapse, and Apple's Deepfake Incident] (Accessed Oct 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;coinmarketcap-16149&amp;quot;&amp;gt;[https://coinmarketcap.com/community/articles/6701d09354de5a1601907b55/ Over 20 Crypto Hacks in September 2024: Here’s How Much Was Stolen: Guest Post by CryptoPotato_News | CoinMarketCap] (Accessed Oct 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;bscscan-16150&amp;quot;&amp;gt;[https://bscscan.com/address/0x7057f3b0f4d0649b428f0d8378a8a0e7d21d36a7 BEP20USDT | Address 0x7057f3b0f4d0649b428f0d8378a8a0e7d21d36a7 | BscScan] (Accessed Oct 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;dexscreener-16151&amp;quot;&amp;gt;[https://dexscreener.com/bsc/0x83681f67069a154815a0c6c2c97e2daca6ed3249 https://dexscreener.com/bsc/0x83681f67069a154815a0c6c2c97e2daca6ed3249] (Accessed Oct 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;geckoterminal-16152&amp;quot;&amp;gt;[https://www.geckoterminal.com/bsc/pools/0x83681f67069a154815a0c6c2c97e2daca6ed3249 CUT/USDT - CUT Price on Pancakeswap V2 (BSC) | GeckoTerminal] (Accessed Oct 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;coinmarketcap-16153&amp;quot;&amp;gt;[https://coinmarketcap.com/dexscan/bsc/0x83681f67069a154815a0c6c2c97e2daca6ed3249/ CUT/USDT Real-time On-chain PancakeSwap v2 (BSC) DEX Data] (Accessed Oct 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;verichainsblog-16154&amp;quot;&amp;gt;[https://blog.verichains.io/p/cut-incident-price-manipulation Cut Incident - Price Manipulation - by lifebow - Verichains] (Accessed Oct 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;certikcntwitter-16155&amp;quot;&amp;gt;[https://twitter.com/CertiK_CN/status/1833926212890361981 @CertiK_CN Twitter] (Accessed Oct 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;tenarmoralerttwitter-16156&amp;quot;&amp;gt;[https://twitter.com/TenArmorAlert/status/1834253188087558368 @TenArmorAlert Twitter] (Accessed Oct 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;0xcommitauditstwitter-16157&amp;quot;&amp;gt;[https://twitter.com/0xCommitAudits/status/1835501273514234199 @0xCommitAudits Twitter] (Accessed Oct 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;metatrustalerttwitter-16158&amp;quot;&amp;gt;[https://twitter.com/MetaTrustAlert/status/1833519534143377924 @MetaTrustAlert Twitter] (Accessed Oct 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;exvulsectwitter-16159&amp;quot;&amp;gt;[https://twitter.com/EXVULSEC/status/1833514743451292146 @EXVULSEC Twitter] (Accessed Oct 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;linkedin-16160&amp;quot;&amp;gt;[https://www.linkedin.com/posts/yogendra-singh-diwan-302a67178_cryptosecurity-blockchain-smartcontract-activity-7241754539291226112-m1m9 Caterpillar Coin hit by flashloan attack | YOGENDRA SINGH DIWAN posted on the topic | LinkedIn] (Accessed Oct 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;newsletter-16161&amp;quot;&amp;gt;[https://newsletter.blockthreat.io/p/blockthreat-week-37-2024 BlockThreat - Week 37, 2024] (Accessed Oct 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;coinlive-16162&amp;quot;&amp;gt;[https://www.coinlive.com/news-flash/620962 Crypto Hack Weekly Report: Indodax Heist, Caterpillar Coin Collapse, and Apple’s Deepfake Incident] (Accessed Oct 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;halborn-16163&amp;quot;&amp;gt;[https://www.halborn.com/blog/post/month-in-review-top-defi-hacks-of-september-2024 Month in Review: Top DeFi Hacks of September 2024] (Accessed Oct 16, 2024)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;certik-16164&amp;quot;&amp;gt;[https://www.certik.com/resources/blog/caterpillar-coin-cut-token-incident-analysis https://www.certik.com/resources/blog/caterpillar-coin-cut-token-incident-analysis] (Accessed Oct 16, 2024)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>