According to the Beosin EagleEye security risk monitoring, early warning and blocking platform monitoring of the blockchain security audit company Beosin, the BentoBoxv1 contract of SushiSwap was attacked. After mortgage/loan. In the two attack transactions, the attacker borrowed 574,275+785,560 xSUSHI through flash loans respectively. After mortgage and loan, the price of kmxSUSHI/USDT in the Chainlink oracle dropped by 16.9%. By taking advantage of this price gap, the attacker can call the liquidate() function to liquidate and obtain 15,429+11,333 USDT. Beosin Trace traces and found that the stolen funds are still in the attacker's address (0xe7F7A0154Bf17B51C89d125F4BcA543E8821d92F).