Traders Spur Volatility After GPC Token Price Manipulation in MSCST Flash Loan Exploit

Generated by AI AgentMira SolanoReviewed byAInvest News Editorial Team
Monday, Dec 29, 2025 2:19 am ET2min read
Aime RobotAime Summary

- A flash loan attack exploited a missing access control in MSCST's contract, causing $130,000 losses by manipulating GPC token prices on BSC.

- BlockSec's Phalcon system detected the anomaly, highlighting recurring DeFi vulnerabilities through smart contract weaknesses in liquidity pools.

- The incident intensified calls for stronger security audits and access controls, as DeFi projects face growing risks from rapid flash loan exploits.

- Investors are urged to prioritize project due diligence, with experts warning of financial risks in under-verified DeFi platforms following this breach.

A flash loan attack on the BSC on-chain project MSCST resulted in losses of approximately $130,000 on December 29. The vulnerability was traced to a missing access control in the contract's releaseReward() function, enabling the attacker to manipulate the GPC token's price in the

liquidity pool . BlockSec's Phalcon monitoring system detected the unusual activity and alerted the community.

The exploit highlighted once again the vulnerabilities inherent in decentralized finance protocols. Flash loan attacks have become a recurring issue for DeFi projects, often exploiting smart contract weaknesses. This attack on MSCST follows similar incidents in the past year, raising concerns among investors and developers.

The incident has reignited discussions about the need for stronger security measures in DeFi platforms. Smart contract audits and proper access control mechanisms are increasingly being emphasized as essential components for project security. As the DeFi space continues to expand, experts warn that vulnerabilities like these can have significant financial consequences.

Market Reactions and Security Concerns

Following the attack, the price of the GPC token experienced volatility as the liquidity pool was manipulated. Traders and investors closely monitored the situation for signs of further instability or potential recovery measures by the MSCST team. The attack also prompted broader concerns about the safety of funds in smaller, less-verified DeFi projects.

BlockSec and other cybersecurity firms have been increasingly vocal about the need for transparency and robust security frameworks in the DeFi ecosystem. While the attack did not compromise the broader BSC network, it exposed weaknesses in individual projects, which can erode trust in the broader DeFi space.

Regulators and market analysts are also keeping a close watch on how such attacks are handled. In the past, similar events have led to increased scrutiny and calls for better oversight in the crypto industry. However, no regulatory response has been announced so far regarding the MSCST incident.

What This Means for Investors

For investors in DeFi and other blockchain-based projects, the MSCST attack underscores the importance of due diligence. While the promise of high returns remains a key attraction to DeFi, the risks associated with unverified projects are substantial. Investors are advised to conduct thorough research and assess the security posture of projects before committing funds.

The attack also highlights the role of liquidity pools in DeFi and the potential for manipulation when contracts are not properly secured. Flash loan attacks, in particular, have proven to be a favored method for hackers due to their speed and ability to exploit price discrepancies in a short amount of time.

In response to the incident, the MSCST team has reportedly begun an internal review and is working with cybersecurity experts to assess the full scope of the breach. While no official statement has been made, the community is awaiting further updates on potential recovery actions or compensation plans for affected users.

Comments



Add a public comment...
No comments

No comments yet