{"investigation":{"slug":"mscst","entity_name":"MSCST (MSC Protocol)","trust_score":22,"severity_base":null,"score_modifier":0,"confidence":0.72,"status":"published","content_type":"investigation","summary":"MSCST is a BSC-based DeFi auto-staking token associated with MSC Protocol (MetaSuperCoin), which advertised an implausible fixed APY of 38,585% over 400 days with no public team or audits. On December 29, 2025, a flash loan attacker exploited a missing access control vulnerability in the protocol's releaseReward() function, draining approximately $130,000 (149 BNB) from the GPC/WBNB PancakeSwap liquidity pool. The project has been flagged by ZachXBT and received no recovery response from an identifiable development team.","sections":[{"content":"MSC Protocol, whose on-chain token is identified as MSCST on Binance Smart Chain (BSC), was publicly announced on June 26, 2022 via GlobeNewswire out of Chicago, Illinois. The project describes itself as 'a decentralized financial solution that rewards holders with a sustainable fixed compound interest model.' Its primary token, MetaSuperCoin (MSC), allegedly provides 1.5% daily compound interest automatically in users' wallets without the need for staking or liquidity provision. The project also includes an NFT component branded SpaceX9, cross-chain bridge functionality, and a DAO governance structure. The contract address for MSCST on BSC is 0xccd04073f4bdc4510927ea9ba350875c3c65bf81. No public development team, founding individuals, company registration, or formal legal entity has been identified in any available documentation.","heading":"Project Overview","sources":[{"url":"https://www.globenewswire.com/news-release/2022/06/26/2469107/0/en/MSC-Protocol-Redefined-protocol-for-sustainable-digital-asset.html","name":"globenewswire.com","type":"other","credibility":3},{"url":"https://msc-protocol.gitbook.io/msc-protocol-ecology","name":"msc-protocol.gitbook.io","type":"other","credibility":3},{"url":"https://blog.verichains.io/p/mscst-flash-loan-attack-price-manipulation","name":"blog.verichains.io","type":"other","credibility":3}],"severity":"medium"},{"content":"MSC Protocol advertised a fixed APY of 38,585% over a 400-day period, or 1.5% compounding daily, which the project described as 'the highest fixed APY in the industry.' Such yields are not economically sustainable without a constant inflow of new capital and are structurally characteristic of Ponzi-type schemes. Transaction fees are structured as follows: 2.5% of each transaction is burned, 2.5% flows to the 'MSCP Eco Fund,' and 5% goes to the 'MSCP Foundation.' No independent smart contract audit has been identified in public records. No third-party risk disclosure or formal prospectus was filed with any regulatory body. The protocol's NFT component, SpaceX9, offered dividend-sharing to early purchasers contingent on a minimum holding of 1,000 MSC tokens, a structure that has drawn comparisons to investment contracts in regulatory literature. These characteristics — anonymous team, extraordinary fixed returns, fee-based reward redistribution, and no audits — represent multiple recognized indicators of high-risk or fraudulent DeFi projects.","heading":"Yield Claims and Tokenomics Red Flags","sources":[{"url":"https://www.globenewswire.com/news-release/2022/06/26/2469107/0/en/MSC-Protocol-Redefined-protocol-for-sustainable-digital-asset.html","name":"globenewswire.com","type":"other","credibility":3},{"url":"https://msc-protocol.gitbook.io/msc-protocol-ecology","name":"msc-protocol.gitbook.io","type":"other","credibility":3},{"url":"https://www.crypto-reporter.com/newsfeed/msc-protocol-redefined-protocol-for-sustainable-digital-asset-33289/","name":"crypto-reporter.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On December 29, 2025, the MSCST smart contract on BSC was exploited via a flash loan attack, resulting in the theft of approximately 149 BNB valued at roughly $130,000 at the time of the incident. The exploit was first detected by BlockSec's Phalcon monitoring system and subsequently reported by multiple crypto news outlets. The root cause was a missing access control (ACL) check in the contract's releaseReward() function. This function accepted an arbitrary amount parameter, swapped half of the specified amount from MSC tokens to GPC tokens, and then transferred the resulting GPC directly into the GPC/WBNB PancakeSwap liquidity pool — all without verifying that the caller had any authorization to trigger the function. The attacker (wallet: 0xB0720D8541cD2b6fC35cCC39ec84e84383A7000b) borrowed 46.8 million GPC tokens via a flash loan, swapped the entire position for approximately 205 BNB on PancakeSwap, which artificially collapsed the GPC price. The attacker then called releaseReward(), which caused the contract to add MSC-to-GPC swap output directly into the manipulated pool. The attacker then bought back GPC at the depressed price, repaid the flash loan, and retained approximately 149 BNB in profit. The attack was completed within a single transaction (hash: 0x53fe7ef190c34d810c50fb66f0fc65a1ceedc10309cf4b4013d64042a0331156). No patch, post-mortem, or user compensation was subsequently identified in public records.","heading":"Flash Loan Exploit — December 29, 2025","sources":[{"url":"https://blog.verichains.io/p/mscst-flash-loan-attack-price-manipulation","name":"blog.verichains.io","type":"other","credibility":3},{"url":"https://www.panewslab.com/en/articles/47855b7f-1a7b-44b2-a938-53c5d168097d","name":"panewslab.com","type":"other","credibility":3},{"url":"https://www.kucoin.com/news/flash/bsc-chain-mscst-project-hit-by-flash-loan-attack-suffers-130-000-loss","name":"kucoin.com","type":"other","credibility":3},{"url":"https://www.weex.com/news/detail/bsc-on-chain-mscst-project-suffers-flash-loan-attack-loses-approximately-130000-290212","name":"weex.com","type":"other","credibility":3},{"url":"https://www.rootdata.com/news/484283","name":"rootdata.com","type":"other","credibility":3}],"severity":"medium"},{"content":"The flash loan attack caused significant price manipulation of the GPC token in the GPC/WBNB PancakeSwap liquidity pool (pool address: 0x12da). The forced sell of 46.8 million GPC tokens in a single block caused an abrupt and severe price dislocation, after which traders reportedly responded to the volatility. Lookonchain, an on-chain analytics platform, documented the incident as it unfolded on BSC. The attacker's address and transaction remain traceable on-chain. There is no public record of the stolen funds being recovered or frozen. The MSCST contract address (0xccd04073f4bdc4510927ea9ba350875c3c65bf81) remains identifiable on BSC explorers. The full scope of user losses beyond the directly extracted 149 BNB, including secondary token price damage to holders of MSC and GPC, has not been independently quantified.","heading":"On-Chain and Market Impact","sources":[{"url":"https://www.lookonchain.com/feeds/41934","name":"lookonchain.com","type":"other","credibility":3},{"url":"https://www.ainvest.com/news/traders-spur-volatility-gpc-token-price-manipulation-mscst-flash-loan-exploit-2512/","name":"ainvest.com","type":"other","credibility":3},{"url":"https://blog.verichains.io/p/mscst-flash-loan-attack-price-manipulation","name":"blog.verichains.io","type":"other","credibility":3}],"severity":"medium"},{"content":"Security researchers at Verichains identified three primary failure modes in the MSCST contract: (1) absence of any access control on the releaseReward() function, which should have been restricted to an authorized caller such as the contract owner or a multisig; (2) reliance on spot price from PancakeSwap rather than a time-weighted average price (TWAP) oracle, making the protocol trivially susceptible to single-block price manipulation; and (3) no slippage protection on DEX swap calls within the contract logic. No public audit report for MSCST or the broader MSC Protocol has been identified by any recognized blockchain security firm such as CertiK, PeckShield, Quantstamp, or SlowMist. The absence of an audit, combined with the critical vulnerability in a core reward-dispensing function, indicates the contract was deployed without standard security review practices. The BlockSec Phalcon system, which monitors on-chain transactions for anomalous behavior, detected the incident in real time.","heading":"Security Assessment and Lack of Audit Record","sources":[{"url":"https://blog.verichains.io/p/mscst-flash-loan-attack-price-manipulation","name":"blog.verichains.io","type":"other","credibility":3},{"url":"https://www.bitget.com/news/detail/12560605125098","name":"bitget.com","type":"other","credibility":3},{"url":"https://hacked.slowmist.io/en/?c=BSC","name":"hacked.slowmist.io","type":"other","credibility":3}],"severity":"medium"},{"content":"MSCST has been flagged by ZachXBT, the pseudonymous blockchain investigator known for tracking DeFi exploits and scam projects across multiple chains. ZachXBT joined Paradigm as an incident response advisor in February 2025 and has assisted in recovering over $350 million in stolen crypto funds across various cases. The specific nature and timing of ZachXBT's flag of MSCST have not been independently verified through a publicly accessible post at time of writing. The project received no known public defense, rebuttal, or team statement following the exploit or ZachXBT's reported flag. Community sources and crypto media broadly characterized the project as an example of insufficiently audited, high-yield auto-staking schemes that are structurally vulnerable to flash loan attacks. No user compensation, recovery fund, or governance vote has been documented.","heading":"ZachXBT Flag and Community Response","sources":[{"url":"https://en.wikipedia.org/wiki/ZachXBT","name":"en.wikipedia.org","type":"other","credibility":3},{"url":"https://www.panewslab.com/en/articles/47855b7f-1a7b-44b2-a938-53c5d168097d","name":"panewslab.com","type":"other","credibility":3},{"url":"https://www.weex.com/news/detail/bsc-on-chain-mscst-project-suffers-flash-loan-attack-loses-approximately-130000-290212","name":"weex.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2022-06-26","event":"MSC Protocol (MetaSuperCoin / MSCST) publicly announced via GlobeNewswire, advertising 38,585% APY and auto-compounding rewards on BSC.","source":""},{"date":"2025-12-29","event":"MSCST contract exploited via flash loan attack on BSC. Attacker (0xB0720D8541cD2b6fC35cCC39ec84e84383A7000b) borrowed 46.8M GPC tokens, manipulated GPC/WBNB PancakeSwap pool price, and extracted approximately 149 BNB (~$130,000) by calling the unprotected releaseReward() function.","source":""},{"date":"2025-12-29","event":"BlockSec Phalcon monitoring system detects the suspicious transaction on BSC targeting MSCST and issues alert.","source":""},{"date":"2025-12-29","event":"Multiple crypto outlets including PANews, Bitget News, KuCoin, WEEX, and Lookonchain report the exploit. Verichains publishes technical post-mortem.","source":""}],"sources_used":[{"url":"https://www.globenewswire.com/news-release/2022/06/26/2469107/0/en/MSC-Protocol-Redefined-protocol-for-sustainable-digital-asset.html","name":"globenewswire.com","type":"other","archive_url":"https://web.archive.org/web/20260829090137/https://www.globenewswire.com/news-release/2022/06/26/2469107/0/en/MSC-Protocol-Redefined-protocol-for-sustainable-digital-asset.html","credibility":3,"archive_timestamp":"2026-08-29T09:01:37+00:00"},{"url":"https://msc-protocol.gitbook.io/msc-protocol-ecology","name":"msc-protocol.gitbook.io","type":"other","archive_url":"https://web.archive.org/web/20260829081321/https://msc-protocol.gitbook.io/msc-protocol-ecology","credibility":3,"archive_timestamp":"2026-08-29T08:13:21+00:00"},{"url":"https://blog.verichains.io/p/mscst-flash-loan-attack-price-manipulation","name":"blog.verichains.io","type":"other","archive_url":"http://web.archive.org/web/20260515164550/https://blog.verichains.io/p/mscst-flash-loan-attack-price-manipulation","credibility":3,"archive_timestamp":"2026-05-15T16:45:50+00:00"},{"url":"https://www.crypto-reporter.com/newsfeed/msc-protocol-redefined-protocol-for-sustainable-digital-asset-33289/","name":"crypto-reporter.com","type":"other","archive_url":"https://web.archive.org/web/20260829045718/https://www.crypto-reporter.com/newsfeed/msc-protocol-redefined-protocol-for-sustainable-digital-asset-33289/","credibility":3,"archive_timestamp":"2026-08-29T04:57:18+00:00"},{"url":"https://www.panewslab.com/en/articles/47855b7f-1a7b-44b2-a938-53c5d168097d","name":"panewslab.com","type":"other","archive_url":"https://web.archive.org/web/20260829181309/https://panews.io/articles/47855b7f-1a7b-44b2-a938-53c5d168097d","credibility":3,"archive_timestamp":"2026-08-29T18:13:09+00:00"},{"url":"https://www.kucoin.com/news/flash/bsc-chain-mscst-project-hit-by-flash-loan-attack-suffers-130-000-loss","name":"kucoin.com","type":"other","archive_url":"https://web.archive.org/web/20260829122426/https://www.kucoin.com/news/flash/bsc-chain-mscst-project-hit-by-flash-loan-attack-suffers-130-000-loss","credibility":3,"archive_timestamp":"2026-08-29T12:24:26+00:00"},{"url":"https://www.weex.com/news/detail/bsc-on-chain-mscst-project-suffers-flash-loan-attack-loses-approximately-130000-290212","name":"weex.com","type":"other","archive_url":"https://web.archive.org/web/20260829232308/https://www.weex.com/news/detail/bsc-on-chain-mscst-project-suffers-flash-loan-attack-loses-approximately-130000-290212","credibility":3,"archive_timestamp":"2026-08-29T23:23:08+00:00"},{"url":"https://www.rootdata.com/news/484283","name":"rootdata.com","type":"other","archive_url":"https://web.archive.org/web/20260829052116/https://www.rootdata.com/news/484283","credibility":3,"archive_timestamp":"2026-08-29T05:21:16+00:00"},{"url":"https://www.lookonchain.com/feeds/41934","name":"lookonchain.com","type":"other","archive_url":"http://web.archive.org/web/20251229074504/https://lookonchain.com/feeds/41934","credibility":3,"archive_timestamp":"2025-12-29T07:45:04+00:00"},{"url":"https://www.ainvest.com/news/traders-spur-volatility-gpc-token-price-manipulation-mscst-flash-loan-exploit-2512/","name":"ainvest.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://www.bitget.com/news/detail/12560605125098","name":"bitget.com","type":"other","archive_url":null,"credibility":3,"archive_timestamp":null},{"url":"https://hacked.slowmist.io/en/?c=BSC","name":"hacked.slowmist.io","type":"other","archive_url":"http://web.archive.org/web/20260724212641/https://hacked.slowmist.io/en/?c=BSC","credibility":3,"archive_timestamp":"2026-07-24T21:26:41+00:00"},{"url":"https://en.wikipedia.org/wiki/ZachXBT","name":"en.wikipedia.org","type":"other","archive_url":"http://web.archive.org/web/20260711020137/https://en.wikipedia.org/wiki/ZachXBT","credibility":3,"archive_timestamp":"2026-07-11T02:01:37+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:14.322297+00:00","updated_at":"2026-08-29T23:26:10.671886+00:00"}}