Hacks
Reproduced Exploits
Root cause, vulnerable code, attack walkthrough, and a standalone Foundry PoC for each incident — an indexed library of reproduced on-chain exploits across EVM chains.
Indexed
1549 / 1549
Atomic (AtomicLending) — Signature Replay + Flash-Loan Spot Manipulation on Arbitrum (~$29,984)
Loss · ~$29,984.27 USDC (native USDC on Arbitrum)
Two independent alerts describe the same drain from two depths:
Base Unverified Arbitrary CALL — Allowance Drain via 0x42be3129
Loss · ~16.623 WETH (~$31k, SlowMist TI)
1. An unverified Base contract holds a privileged pattern: a public function that performs a low-level CALL to an arbitrary target with attacker-controlled calldata (Slo…
LpdFi — Spot-Oracle Price Manipulation Drains Protocol LP via claimInterest
Loss · ~693,529.79 USDC (~$690K) drained from protocol LPD/USDC LP in the claim tx; public repor…
1. LpdFi is a staking product. Users deposit LPD, open an “order” denominated in a notional uAmount (USDC units), and earn 0.5%/day interest (capped at 50% of uAmount).…
MOKE LP Dividend Drain — Stale `userLPRecord` Double-Claim via Unsynced LP Transfers
Loss · ~$907.7K (~1,546.5 BNB net to the attacker in the live tx; PoC drains ~1,639 BNB of a 1,6…
1. MokeLPDividend pays BNB dividends proportional to MOKE/WBNB LP holdings, using a MasterChef-style debt model: userLPRecord, userDividendDebt, and global totalDividend…
NEX/AIC FoT Skim — Router Double-Transfer + Sell Fee Lets skim() Empty the Pair
Loss · ~32.36 BNB (~$19.1K) (32361267289208020008 wei) — exact match to the live attack tx
1. NEX is a fee-on-transfer token with a 6% dao sell fee when the recipient is an AMM pair, and a special branch that is meant to skip fees when either side of the trans…
StrongBlock Governance Takeover — Abandoned Governor → Malicious Upgrade → Pool Drain
Loss · ~$72K — 32,695.76 STRONG + 383,447.17 STRNGR
1. StrongBlock left an on-chain Governor with live upgrade authority, while the STRONG vote token was economically worthless — so majority voting power was cheap. 2. Att…
Unistreets LaunchpadFactoryAuto — Arbitrary Calldata Injection → V4 LP Burn (2-tx, 2-victim confused deputy)
LaunchpadFactoryAuto is the ERC-721 owner of the Uniswap v4 liquidity position minted for every token it launches. Its launch() function takes a caller-controlled modify…
USM / FUM (Minimalist USD) — Flash-loan fund/defund extracts ETH buffer via inflated mid-price
Loss · ~70.83 ETH (~$160K) drained from the USM ETH pool; PoC profit 70.831554410317728328 WETH
1. Minimalist USM is an ETH-backed stablecoin; FUM is the buffer/equity token. Users fund() ETH to mint FUM and defund() FUM to redeem ETH from the shared pool.
ZKPanther (Base) — Reality.eth governance module → proxy upgrades → ZKP drain
Loss · ~5.12M ZKP (~$15.6k at ~$0.003/ZKP) + ~0.123 ETH; team: Base zone not yet in production,…
1. Panther’s Base DAO is a Gnosis Safe with a Zodiac RealityModuleETH clone: anyone can addProposal, and a Reality.eth “yes” answer with only a 0.5 ETH bond becomes exec…
BarnBridge SMART Yield — Governance Capture of an Abandoned DAO → Controller Swap → Approval Drain
Loss · 776,575.547933 USDC (drain #1 774,943.379409 + drain #2 1,632.168524)
---
Bonzo Lend / Supra Oracle — BLS Zero-Signature Price Forgery
Loss · ~$9.05M Wallet A principal (BlockSec / Bonzo Finance; excludes ~$1.0M white-hat Wallet B)
1. Bonzo Lend prices ecosystem collateral (including SAUCE) from Supra's on-chain pull-oracle feed. It does not re-verify committee signatures; it reads the latest store…
CrowdRingCircle Exploit — Premature `sync()` Turns a Sell-Tax Burn into a Free Reserve Drain
Loss · 201,359.443861203526776802 USDT (~$201.36K) extracted from the CRC/USDT PancakeSwap pair…
CRC is a BEP-20 token with a "sell tax + sell destroy" mechanism: every transfer that lands on a registered DEX pair first skims a 10% fee, then additionally burns up to…
Drips Network DaiDripsHub `give()` — `uint128 → int128` cast flips fund flow
Loss · 24,882.995421947667857715 DAI (full DaiReserve balance at attack block)
1. Drips Network’s DAI hub lets any user call give(receiver, amt) to gift DAI stream collectable balance to a receiver. Accounting debits the giver via a signed _transfe…
Edel xStock — ERC4626 convertToAssets Donation Inflates Collateral and Drains Reserves
Loss · 204,215.57 USDC + multi-asset xStock wrappers (wSPYx/wQQQx/wMSTRx/wNVDAx/wTSLAx)
1. Edel markets treat wrapped xStock tokens (e.g. wGOOGLx) as collateral. Pricing goes through an AaveOracle path that ultimately depends on the wrapper's live convertTo…
Hinkal Shielded Pool — Legacy Note Multi-Nullifier Double-Spend
Loss · ~$800K–$822K USDC (+ other assets) drained from Hinkal privacy pool(s)
1. Hinkal is a shielded pool: deposits become commitments in an on-chain Merkle tree; spends present a ZK proof plus a nullifier. The contract records each nullifier and…
Index Coop ExchangeIssuance TOCTOU — Unlocked SetToken Units + Malicious Manager Hook Drain Residual Inventory
Loss · ~\$9.6K USD (SlowMist TI). PoC drains residual EI inventory including ~436.70 LINK and ~4…
1. Index Coop ExchangeIssuance lets anyone call issueSetForExactToken for any controller-registered SetToken. It reads that SetToken's component real units to size swaps…
Lumi Finance (Sodium ERC-4337 account) — Signature-Bypass Drain
Loss · Multi-asset drain across ~50 Sodium smart accounts (≈ $264k reported). This fork replay m…
Sodium is Lumi Finance's ERC-4337 v0.6 smart-account wallet, and its owner check is forgeable: it trusts a signer address taken from the attacker-supplied UserOperation…
NFT Auction Marketplace Exploit — Settle-Then-Cancel Double Payout Drains the Escrow Pool
Loss · 2.217610999999999999 BNB (~$4.15k) — the marketplace's entire escrowed BNB balance, drain…
The marketplace tracks each listing's escrowed BNB (the buyer's payment) in a single Sale struct keyed by saleId. completeAuction (called via buyNow) transfers the NFT t…
Perpetual Protocol (Curie) Exploit — Missing Access Control on `OrderBook.updateFundingGrowthAndLiquidityCoefficientInFundingPayment()`
Loss · 3,062.213107 USDC.e (=$3,062.21) drained in this single transaction
Perpetual Protocol V2 ("Curie") is a perpetual-futures DEX that reuses Uniswap V3's concentrated-liquidity math as its virtual AMM. Its OrderBook contract tracks each li…
RWT Token Exploit — Owner-Gated `burn()` Lets a Role-Holder Delete an AMM Pair's Own Reserve
Loss · ~118,069.28 USDT extracted in this reproduction (assertApproxEqAbs target ~118,000 USDT);…
RWT (0xf8A3…) ships a custom burn(address _From, uint256 _amount) external onlyOwner that calls _burn(_From, _amount) directly — no allowance check, no restriction on _F…
Sodium Smart Wallet Exploit — ERC-4337 Session-Key Validation Bypass / EntryPoint Gas-Deposit Griefing
Loss · ~11.76 ETH (~$21,200), drained from 300+ Sodium smart-wallet accounts in a single transac…
Sodium is an ERC-4337 smart-contract wallet ("ZK/MPC" marketed) built on a Gnosis-Safe-style architecture: every user gets a minimal proxy that delegatecalls a single sh…
Summer.fi FleetCommander — NAV Inflation via Empty-Ark Donation of Undervalued vgUSDC
Loss · ~5.60M DAI reproduced on FleetA (5597682112787981084159961 wei); full incident ~6.02M inc…
1. Summer.fi Lazy Summer FleetCommander prices shares from the sum of each ark's totalAssets() with no smoothing, donation resistance, or empty-ark gate.
AIDCToken sell-burn drains the AMM pair reserve — deflation logic burns tokens from the LP without a counterpart
Loss · ~220.13 WBNB (≈ $132k at BNB ≈ $600)
AIDC is an ERC-20 ("AI Data Credit") with a custom AMM tax. On every non-whitelisted sell into the PancakeSwap V2 AIDC/WBNB pair, _sellTransfer does not actually burn an…
AISOTH Presale Exploit — Same-Tx Buy+Claim of Below-Market Inventory, Dumped Into the Live AIS/USDT Pair
Loss · 30,314.76 USDT profit to the attacker (30314760842915494215340 wei), extracted from the A…
1. Presale (Presale.sol) sells AIS for USDT at a fixed administrative price of price = 35e15 (i.e. $0.035 per AIS, Presale.sol:58-59). It holds a real inventory of AIS d…
Ambient (CrocSwap) Exploit — Native-ETH Surplus Settlement Drained via a Self-Dealt Grid-Walk + Range Harvest
Loss · ~33.72 WETH + ~55,913.81 USDC extracted from Ambient's ETH/USDC pool in a single tx (33.7…
1. Ambient (CrocSwap) is a single-contract concentrated-liquidity AMM. Every user action — swap, mint, burn, harvest — is dispatched as a userCmd(callpath, cmd) into one…
ATM LP-Burn Exploit — Misplaced LP Tokens Are Burn-Redeemable by Anyone via PancakeV2 `burn()`
Loss · 1,603.99 WBNB redeemed out of the ATM/WBNB pair (~$1.6M-class drain of the pool's WBNB si…
1. The ATM/WBNB pair is a stock PancakeSwap V2 pair (PancakePair, Solidity 0.5.16). Its burn(address to) function redeems liquidity equal to balanceOf[address(this)] — i…
ATM Token Exploit — Per-Address Anti-Whale Guards Sidestepped by 30 Sybil "Farmer" Clones
Loss · ~$243,543 USDT gross drained from the ATM/USDT PancakeSwap pair in the cash-out tx (attac…
ATMToken is a PancakeSwap-listed "tax token" with a thick layer of anti-whale / anti-bot protections bolted onto its custom _transfer() (contracts_ATMToken.sol:85-210).…
ATOHook Solady ReentrancyGuard Storage Collision — Inflated `getReward()` Drain
Loss · 14.411518807585587 ETH (exactly 200 × 0xffffffffffffff wei)
1. ATOHook is a Uniswap v4 hook with a Synthetix-style native ETH reward stream. Accrued balances live in mapping(address => uint256) public rewards at base slot 17.
Aztec Connect (V3) Exploit — `numRealTxs` proof-vs-settlement coverage mismatch
Loss · ~$2.19M total drained from the dormant Aztec Connect privacy bridge. This PoC reproduces…
1. RollupProcessorV3.decodeProof() (Decoder.sol:281) computes the publicInputsHash by SHA256-hashing the transaction data in full inner-rollup chunks. The number of non-…
Aztec Escape-Hatch Exploit (variant 2) — Unconstrained Inner `proof_id` Witness
UntaggedLoss · educational reproduction (the Connect contracts were already drained via exp1); disclosur…
Per the embedded root cause: escape_hatch_circuit.cpp publishes the inner proof id with public_witness_ct(&composer, 0); // proof_id. public_witness_ct() makes the value…
Aztec V1 Escape-Hatch Exploit — Unbacked Withdrawals via Verifier-Trusted Rollup Proofs
Loss · ~$2.2M — 1,158 ETH + 150,000 DAI + 0.46963295 renBTC drained from the Aztec V1 rollup's p…
1. The Aztec V1 rollup exposes escapeHatch(bytes proofData, bytes signatures, bytes viewingKeys) (contracts_RollupProcessor.sol:347-356) — a permissionless exit path. Un…
BOSS Exploit — Helper Mint/Burn Drains the Pair's BOSS Reserve, then a Degenerate-Reserve Swap Loop Empties the USDT Side
Loss · ~10,207.54 USDT (PoC nets 10,210.15 USDT to the attacker EOA) drained from the BOSS/USDT…
1. The attacker borrows 1,250,000 USDT from a Moolah flash loan (output.txt:67) and enters its own onMoolahFlashLoan callback. 2. It calls the privileged BOSS helper's u…
BY Token Exploit — Permissionless `triggerAutoBurn()` Pool-Reserve Drain
Loss · ~$87,402 — 146.60 WBNB drained from the BY/WBNB PancakeSwap pair
BYToken is a deflationary token whose _autoBurn() routine, when the token contract's own balance is insufficient, burns BY tokens directly out of the AMM pair's balance…
Cook Finance Issuance — Caller-Chosen Weightings Drain CKToken Components via Thin Pancake Pools
Loss · ~2.82 BNB net profit to the attacker (2816924852223933205 wei), extracted from a Cook Fin…
1. Cook's IssuanceModuleV2.issueWithSingleToken2 (IssuanceModuleV2.sol:3124-3153) lets anyone mint a CKToken by supplying a single component token and a caller-chosen _w…
DIP Exploit — Fee-on-Sell Transfer + `skim`/`sync` Reserve-Collapse on the DIP/AIC Pair
Loss · ~111,097.59 USDC (PoC header); the trace asserts 111,102.04 USDC profit drained from the…
1. DIP is a PancakeSwap-traded ERC20 with a custom _transfer override (contracts_flatten_nexus_dip.sol:1702-1732) that charges a 6% sell fee (sellFee = 6) on any transfe…
DLMC Exploit — Reserve-Derived `livePrice` Self-Inflation Drains the Token's Own USDT Backing
Loss · ~$222,560 — 222,560.22 USDT drained from DLMCToken's own USDT reserve (output.txt:337); t…
1. DLMCToken is an MLM-style "investment" token. Users buy() LPT with USDT, which is kept inside the token contract, and later sell() LPT back for USDT. The redemption p…
DTXT Exploit — 1-Wei USDT Donation Misclassifies a Sell as a Liquidity Add (Fee Bypass + Stale-Reserve Drain)
Loss · ~35,041.11 USDT drained from the DTXT/USDT PancakeSwap pair (the pool's entire ~35,637 US…
1. DTXT is a fee-on-transfer token. On a sell (a transfer to the AMM pair) it skims a 5% destroy/dividend fee in _transfer (DTXT.sol:933-940). But before charging any fe…
Gnosis Pay / Zodiac Delay — `moduleTxSignedBy` ignores EIP-1271 `staticcall` success
1. Gnosis Pay card accounts are Safe smart accounts with Zodiac Roles + Delay modules. Outgoing non-card transfers queue in Delay for a short cooldown (txCooldown = 180…
JaredFromSubway MEV Bot — Residual ERC-20 Approvals to Untrusted Bait Wrappers
Loss · CertiK ~4,424 ETH (~$7.5M) after stables → ETH conversion; other outlets cite ~$7.5–15M c…
1. Over weeks, an attacker deployed ~66 fake tokens / forged Uniswap-v2-style pairs and bait wrappers that looked like profitable sandwich / multi-hop arb opportunities…
JB Exploit — Gateway-Driven `sell → PoolBurn(pool) + sync()` AMM-Reserve Drain (Venus-leveraged)
Loss · 49,958.06 USDT — drained from the JB/USDT PancakeSwap pair via the JB gateway (BSC; 18-de…
1. The attacker takes a free WBNB flash loan of 417,464.10 WBNB from a permissionless flash lender (output.txt:1646), supplies all of it to Venus as collateral (vWBNB.mi…
LBP (Little Boy Plus) Exploit — Reserve-Manipulated LP-Credit Inflates Mining Rewards Minted Into the Pool
Loss · 610.56 BNB total (≈ 592.41 BNB to the profit receiver + 5 BNB builder tip + gas/dust). Ne…
1. LBP is an immutable ERC-20 whose mining/hashrate accounting lives in a sibling contract LBPHashrate. Adding LP to the LBP/USDT pair grants the LP source hashrate, and…
Lixir vault `permit` signature bypass — any holder's vault shares drained with a forged signature
Loss · 2.60 ETH, 4,477.72 USDC, 3,609.95 USDT, 24,182.56 LIX (≈ $33k at the time)
Lixir is a Uniswap-v3 active-liquidity manager. Users deposit into a per-pair vault (an ERC-20 "Lixir vault token", lv_X-Y A/B) and the vault parks the liquidity inside…
NovaBox Exploit — Stale Dividend Checkpoint on Join + Constructor `extcodesize` Bypass
Loss · 56.73 ETH drained from the NovaBox dividend pot (~56.729621359923131444 ETH net profit as…
1. NovaBox is a 2018-era "ETH+NOVA dividend box" written in Solidity 0.4.25. Depositing ETH or NOVA levies an 11% fee; the fee is distributed to existing dual-asset depo…
Ocean Protocol BPool / SideStaking gulp drain — pool internal records desynced from real token balance, harvestable via single-sided joins + exits
Loss · ~127,861 mOCEAN (minter-share / vesting token; attacker ends with 127,861.011180850512933…
Ocean Protocol runs a fork of Balancer's BPool (contracts/pools/balancer/BPool.sol) wired to a SideStaking helper (contracts/pools/ssContracts/SideStaking.sol). Each poo…
OLPC Exploit — Owner `decimalsValue` Misconfig Amplifies Pair-Side Burn → `amountIn=0` Supporting-Fee Drain
Loss · ~1,115,903.66 USDT drained — the OLPC/LABUBU pair's LABUBU reserve was routed out through…
1. OLPCToken overrides ERC20 _update (OLPCToken.sol:1403-1481). When OLPC leaves the PancakeSwap pair (from == swapPair), the hook burns value decimalsValue OLPC out of…
RoyalRoyalties Exploit — Zero-Amount ERC-1155 Batch Transfer Inflates `tierBalanceOf` 100×
Loss · 261,162.93 USDC — drained from the Royalties payout float on Polygon
1. Royal1155LDA is an ERC-1155 that keeps a custom per-tier balance ledger (_BALANCES_[tierId][owner]) on top of standard ERC-1155 balances. The Royalties contract reads…
Thetanuts Exploit — Zero-Cost Index-Vault `mint()` via Rounding-Down Component Deposits
Loss · 105,471.50 USDC drained (plus residual AVAX/BNB/MATIC component-vault shares forwarded to…
1. The Thetanuts index vault is an "index of vaults": one index share is backed by a pro-rata basket of component vault shares (BTC-USD, ETH-USD, AVAX-USD, BNB-USD, MATI…
Thetanuts Finance Exploit — Integer-Division Truncation in `mint()` After the Vault Is Drained to ~0 `totalSupply`
Loss · ~$2.1M real-world (≈$2M rescued by a whitehat per the post-mortem). The reproduced PoC re…
1. The vault is a basket-share token: holding one share entitles you to a pro-rata slice of five underlying option tokens. mint(amount) is supposed to pull a deposit of…
TOP Exploit — Aragon Instant-Execution Governance Self-Mint + Balancer BPool Drain
Loss · 944.195477215074054197 WETH (~944.20 WETH) drained from the Balancer TOP/WETH BPool; atta…
1. TOP governance is built on Aragon: an AppProxyUpgradeable-fronted Voting app whose execution scripts run with the TokenManager's MINT_ROLE, plus a TokenManager exposi…
Vault4626 — Donation of Non-Asset WETH Inflates totalAssets() and Is Paid Out on redeem()
Loss · ~13.53 WETH profit (18366634484619156667 − 4837426434749649311 = 13529208039869487356 wei)
1. totalAssets() (Vault4626.sol:496-536) returns idle USDC + LP value plus TWAP-quoted vault balances of the non-asset token (WETH):
WHALE Exploit — Flash-Inflated AMM Reserve → Mining-Hashrate Over-Credit Drain
Loss · ~$3,460 — 3,460.42 USDT forwarded to the attacker EOA after repaying every borrow (output…
1. WHALE is a deflationary BSC token bolted onto a "mining / hashrate" reward engine. Adding liquidity to the WHALE/USDT pair credits the LP-adder a hashrate balance in…
Adshares Bridge Exploit — Compromised Minter Key Fabricates Cross-Chain Mints
Loss · ~$628K — 1,199,999.81 wADS minted from nothing (3 fake "wrap" mints)
WrappedADS is the Ethereum side of the Adshares cross-chain bridge. The native ADS chain is supposed to be the source of truth: a user locks ADS natively, an off-chain r…
AROS Exploit — Leaked `claimSigner` Key + AMM-Reserve Drain via Signed Claims
Loss · ~$295,314 — 295,314.04 USDT drained from the AROS/USDT PancakeSwap pair (the pool's entir…
AROS is a UUPS-upgradeable ERC20 with an EIP-712 signed claim system. Four claim entry points (claimPrincipal, claimYield, claimLucky, claimContribution) let a user pull…
Aurellion Labs Diamond Re-Init Drain — Unprotected `initialize` → `diamondCut` pull/sweep
Loss · 456,442.536622 USDC (~$456K) to attacker EOA
1. Users had granted unlimited USDC allowances to the Aurellion diamond 0x0adc…. That alone is normal; the bug is that the diamond’s ownership / init surface remained op…
BlastFOMOVault `claimBonus` clone-churn drains BNB bonus pool
Loss · 1.289508079648543283 BNB offline (historical on-chain ~1.288418562948543283 BNB)
1. BlastFOMOVault turns buy-tax BNB into a decaying hype meter. When hype crosses threshold, Blast Mode opens and anyone can call claimBonus(referrer). 2. Each successfu…
BoostHook Leveraged Long Exploit — Spot open without post-open solvency + `MAX_LIQS_PER_BLOCK` cascade cap
Loss · ~20.9329 WETH attacker profit; ≥38.327 ETH realized totalBadDebtETH; ~34.9 ETH residual o…
1. BoostHook is a Uniswap v4 hook that lets users open leveraged long positions: user posts ETH collateral, the hook borrows more ETH from bonding-curve bands, swaps col…
DxSale Liquidity-Locker Exploit — Stealthy Ownership Takeover + Privileged Drain (~$7.3M BNB)
Loss · ~$7.3M in BNB across 1,400+ locked LP positions (per public post-mortems)
DxSale's liquidity lockers are custodial: users send their LP tokens to a locker contract and trust the contract to refuse withdrawals until each user's timelock elapses…
Ekubo Protocol Exploit — Flash-Accounting `pay()` Funded From a Victim's Standing Approval
Loss · ~$1.4M — 17.0 WBTC (1,700,000,000 at 8 decimals) drained from a single approving user
Ekubo is a singleton-style concentrated-liquidity DEX (the "all the tokens live in one Core contract" design, like Uniswap V4). All interactions happen inside a flash-ac…
ElevateFi Exploit — Fixed-USD Staking Packages Priced from Spot DAI/EFI Reserves
Loss · ~$16,000 — 6,264.86 EFI paid out of the ElevateFi staking vault (asserted profit 62648645…
1. ElevateFi's staking implementation lets a user open a fixed-USD package (e.g. package 7 = $25,000) by calling stakeEFI(packageId) (Staking_Implementation.sol#L1575-L1…
Fractal Protocol Exploit — Stale-Price / Retroactive-Yield Arbitrage via Permissionless `compute()`
Loss · 13,707.72 USDC.e (13,707,715,574 raw, 6 dp) — ≈ $13.7K, the entire withdrawal buffer + ac…
Fractal's Vault is a yield-bearing wrapper: you deposit() USDC.e and receive USDF receipt tokens priced at an internal tokenPrice (≈ how many USDC.e one USDF is worth).…
HeisenbergHook Fee Path Hijack — Unrestricted `poolKey` overwrite + permissionless `processFees`/`processBurn`
Loss · 0.425919592403168892 ETH attacker profit (gas-free PoC; on-chain net after ~0.0044 ETH ga…
1. HeisenbergHook is a Uniswap v4 hook for the $HEIST / ETH pool. Sell-side fees accumulate as pendingFeeHEIST (~5,261 HEIST pre-attack); buy-side fees split into treasu…
Huma Finance Exploit — Evaluation-Agent Approval Bypass via `refreshAccount()`
Loss · ~$101,390 — 82,315.571243 USDC + 19,074.730601 USDC.e drained from three Huma credit pool…
1. Huma Finance runs on-chain credit pools where large credit lines are supposed to be gated behind a privileged off-chain underwriter, the Evaluation Agent (EA). Only t…
INK Finance Exploit — Flash-Loan-Inflated, Permissionless `claimPayroll()` Treasury Drain
Loss · ~$140,180 — 140,180.175562 USDT0 (the treasury's entire balance)
INK Finance is a Polygon "on-chain payroll / DAO treasury" product. Employees are paid out of a shared Treasury vault. The Payroll contract exposes claimPayroll(uint256…
Joe Agent (JOE) Exploit — `removeLiquidityViaContract` Reentrancy on Pooled LP Custody
Loss · ~$45K — 62.5 BNB + 1,848,087 JOE drained from the protocol's pooled LP
JoeAgentToken lets users "zap" native BNB into a JOE/WBNB LP position that is custodied by the token contract itself and merely credited to the user via lpInfo[user].lpA…
LegendaryMoneyMonNft Exploit — `cliamRewred()` Signature Bypass via `ecrecover` → `address(0)` == `admin`
Loss · ~$85,519 — 24,306.53 MON drained from the NFT contract, swapped to 85,519.47 USDT
LegendaryMoneyMonNft.cliamRewred() lets any caller pull an arbitrary ERC20 amount out of the contract, gated only by an off-chain admin signature checked through verify(…
MAP Protocol Exploit — Unverified `retryMessageIn` Forges a Cross-Chain Message to Mint 1e33 MAPO
Loss · ~$180K — 1,000,000,000,000,000 MAPO (1e15 MAPO = 1e33 wei) minted out of thin air to the…
MAP Protocol's OmniService bridge (MOSV3) accepts inbound cross-chain messages through messageIn(...), which is gated by a light-client proof (lightNode.verifyProofDataW…
MetaSea (SEA Token) Exploit — `redeemPosition()` Over-Pays From an Unguarded Reward Distributor
Loss · ~$110K total across the attacker campaign — this single tx nets 13,904.94 USDT and drains…
MetaSea is a USDT "IDO / staking round" product. A user calls openPosition(usdtAmount, …) to deposit USDT; the MetaSea Round contract buys SEA, records the position, and…
Mure Distribution Exploit — Attacker-Controlled `source` Forges Both Verifier and Signature
Loss · ~5.45 ETH (≈ 4,848,683.8 QUEST drained from the victim, swapped to 5.4511 WETH)
MureDistribution is meant to let a user redeem a "distribution" of ERC-20 tokens that was authorized by a trusted pool's signer. The flaw is that nothing about the autho…
New Market Trading Exploit — Payload-Forgery Drain via Axelar "Express" Path on a Gnosis Safe Module
Loss · ~$3.98M total across 88 Gnosis Safes on Ethereum / Base / Arbitrum. This PoC drains one E…
SquidRouterModule is a Gnosis Safe module that lets a Squid/Axelar cross-chain message drive swap/approve actions on a Safe that has installed the module. It inherits Ax…
ONTR Token Zero-Owner `onlyOwner` Free Mint → Pancake WETH Drain
Loss · 49.480100697512152261 WETH (exact wei: 49480100697512152261)
1. ONTR ships a custom Ownable whose onlyOwner is: When ownership has been renounced (owner == 0), any caller is treated as owner.
Renegade Darkpool Exploit — Re-Initializable Proxy → Attacker-Controlled `delegatecall`
Loss · ~$210K — 26 ERC-20 tokens drained from the Darkpool. Largest: 104,383.59 USDC + 0.3466 WB…
The Renegade Darkpool is an upgradeable proxy whose logic lives in an Arbitrum Stylus (Rust) implementation. Its initialize(...) function — which records core protocol a…
Sat1Hook Forensics — Grindable Hook Identity, but No Confirmed Protocol Loss
The initially supplied transaction is not a Sat1Hook drain. It is an MEV backrun placed immediately after a large, ordinary curve redemption. The backrun contract gained…
Sharwa Margin Trading — Uniswap-V3 spot-price oracle used to value NFT collateral
Loss · ~32.85K USDC (32,850 USDC, 6 decimals)
Sharwa's margin-trading protocol accepts ERC-721 collateral (here a Hegic option NFT, tokenId 16129) and values it through a "UniswapModuleWithoutChainlink" module. That…
SKP Token Exploit — Owner Backdoor `ownerBurnLiquidityPairTokens()` Reserve Drain → Collateral Price Inflation
Loss · ~$212K USD — BTCB + USDT borrowed against artificially-inflated SKP collateral on Venus/L…
SKP is a fee-on-transfer "deflationary" BSC token whose owner retained a hidden backdoor: ownerBurnLiquidityPairTokens(uint256) (selector 0x4eb9b26d). When called by the…
SKP/USDT Exit-Scam Drain — Pre-Positioned 96.8%-of-Supply "Whitelist" Treasury + Pool Drain
UntaggedLoss · ~$212,195 USDT on-chain / +233,967.42 USDT net in this PoC (no flash-loan fees) — the SKP…
This is not a conventional external hack — it is an exit scam with a vulnerability-shaped cover story, and the on-chain record proves it. Three facts establish that the…
SQ Token Staking Exploit — Hardcoded Owner Backdoor + Self-Minting Staking Rewards
Loss · ~$346.1K — 346,137.03 USDT drained from the staking contract and its SQi/USDT pool
Staking is an Ownable-derived staking/MLM contract. Its _checkOwner() was modified away from the standard OpenZeppelin implementation to add a second, hardcoded address…
Squid Router Module Exploit — Caller-Supplied Delegate on the Permissionless Axelar Express Path
Loss · 0.25361701 WBTC + 0.293599251 wTAO + ~0.0221 ETH (wrapped) + 0.000000000000001215 WETH —…
1. SquidRouterModule is an enabled module on a Gnosis Safe. It can drive the Safe (execTransactionFromModule) to approve tokens and route swaps — but only after it check…
TesseraSwap Exploit — CEI Violation: Treasury Pays the Output Token Before Collecting the Input Token
Loss · 13,065,334 USDC (6-decimals raw) ≈ $13.07 of USDC siphoned from the Tessera treasury per…
1. TesseraSwap.tesseraSwapWithCallback (src_TesseraSwap.sol:46-65) is a router-style swap: a caller specifies (tokenIn, tokenOut, amountSpecified, …), an off-chain "Tess…
TrustedVolumes Exploit — Permissionless Signer Registration + Wrong-Key Authorization Drains an RFQ Settlement Proxy
Loss · ~$5.87M USD — 1,291.16 WETH + 206,282.45 USDT + 16.939 WBTC + 1,268,771.49 USDC drained f…
TrustedVolumes runs an RFQ (request-for-quote) settlement proxy. A signed order says: a maker gives makerAmount of makerAsset, a taker gives takerAmount of takerAsset. T…
Verus–Ethereum Bridge Exploit — Forged Cross-Chain Import With No Source-Amount Validation
Loss · ~$11.58M — 1,625.367 ETH + 103.568 tBTC + 147,658.84 USDC drained from the bridge's Ether…
Verus is a PBaaS blockchain whose Ethereum bridge lets users move value between Verus and Ethereum. To release funds on Ethereum, the bridge requires a cross-chain impor…
WUSD Exploit — Sybil-Farmable `_englove()` Reward Mint + Thin-Pool GLO Drain
Loss · Reported ~$200K-class incident (free GLOVE emissions + LP drain across the on-chain campa…
WUSD.wrap() mints WUSD against a stablecoin (USDT/USDC) and, as a reward, calls the internal _englove() routine to mint free GLOVE (contracts_WUSD.sol:309-318).
YSDAO Exploit — Balance-vs-Reserve "Add/Remove Liquidity" Tax Bypass + Permissionless `Staking.sync()` Price Pump
Loss · ~19,490.91 USDT (≈ $19.49K) extracted from the YSDAO/USDT PancakeSwap V2 pair
YSDAO is a "fee-on-transfer" token. To avoid taxing legitimate LP mint/burn, its transfer hook tries to guess whether a pair-side transfer is a buy, a sell, an add-liqui…
a152 Authorized-Spender Allowance Drain — privileged spender abused to pull any user's approved tokens
Loss · 228,980.735023 USDT drained and consolidated to the attacker (PoC figure, output.txt:1565…
The victim was an aggregator/spender deployment built on the well-known "AllowanceTarget + SpenderHelper" pattern (identical addresses to 0x Exchange Proxy infra: Allowa…
Blockchain Bets ERC-1155 stake/transform inflates redeemable BCB → UniV2 dump
Loss · 17.568954659981801955 ETH (exact wei: 17568954659981801955)
1. Attacker CREATE-deploys a nested factory at nonce 0 that flash-swaps 4_000_000_000 raw BCB (9 decimals) from the UniV2 BCB/WETH pair. 2. Flash funds are split across…
Giddy YieldBasis VaultV3 — EIP-712 signature only binds swap `data`, not token/amount/aggregator
Loss · ~$1.3M (in three YieldBasis gauge receipt tokens: ~3.53 g(yb-tBTC), ~6.94 g(yb-cbBTC), ~6…
Giddy's YieldBasis vaults (a tBTC, a cbBTC, and a WBTC vault, all sharing the GiddyVaultV3 implementation) compound their strategy rewards through a signed VaultAuth mes…
JUDAO sell-hook reserve drain — token transfer hook burns liquidity directly from its own DEX pair, desyncing the AMM reserves the attacker then arbitrages
Loss · 205,259.49 USDT + 36 BNB (≈ $62k at the time)
JUDAOToken overrides _update (ERC-20 transfer) to install a buy-mining / sell-deflation economy on top of its PancakeSwap JUDAO/USDT pair. The sell branch, entered when…
Juicebox REVLoans Exploit — Trust-on-First-Use of a Caller-Supplied Loan Source Inflates Borrowable Surplus
Loss · ~21.76 ETH — 21.764969886576733610 ETH drained from Juicebox revnet #3's treasury via JBM…
1. REVLoans.borrowFrom() (src_REVLoans.sol:483-560) lets anyone open a loan against a revnet, passing a REVLoanSource{token, terminal} struct of their own choosing. The…
Kipseli PropAMM Exploit — USD-Scale Quote Misread as cbBTC Token Units
Loss · 0.92610395 cbBTC (raw 92,610,395, 8 decimals) drained from a Kipseli-controlled cbBTC hol…
1. PropAMMWrapper.swap(tokenIn, amountIn, tokenOut, minOutAmount, recipient) (src_PropAMMWrapper.sol#L34-L41) is a thin front-end to an external "PropAMM" pricing engine…
MONA / LisaVault Exploit — Self-Referral Node Farming + Insider LP Drain
Loss · 20,357.8 USDT net to the attack contract + 10,000 MONA dividends, sourced from (a) 25,831…
LisaVault sells "nodes." Each node:
PerpPair Exploit — Self-Dealt LP/Trader Pair Inflates Curve-Priced PnL out of the Shared Vault
Loss · 165,617.735181 USDC net profit asserted by the PoC (the real-world incident is quoted at…
PerpPair is a perpetuals AMM. Liquidity providers and traders both post USDC into one shared Vault; profit and loss are settled against that single pool. A position's Pn…
QNT Reserve EIP-7702 + Permissionless `BatchCall.batch()` Drain
Loss · 1,988.546547972979064297 QNT (exact wei: 1988546547972979064297) → swapped to ~54.93 ETH
1. A QNT reserve is controlled under the authority of admin EOA 0xc6ddf907…. 2. That EOA is EIP-7702-delegated to BatchExecutor 0x95538e1c… (designator code 0xef0100 ||…
RWAVault Exploit — Overridden `ERC4626.withdraw` Drops the Allowance Spend
Loss · 398,655.47 USDC total vault outflow (392,763.999994 USDC principal pulled to the attacker…
1. RWAVault is an ERC4626 "real-world-asset" vault that custodies depositors' USDC, mints them shares, and pays monthly interest. At maturity, depositors call withdraw/r…
Saturn Protocol (sUSDat) — Withdrawal Freeze via `strcBalance`/`vestingAmount` Desync + 33% PROCESSOR Extraction
StakedUSDat tracks two pieces of accounting that must stay coupled but are updated by different functions:
sAVAX Rebalancer arbitrary-call drains victim credit delegation — permissionless `target`/`data` execution from a delegated Aave borrower
Loss · 6,999.99 WAVAX (~7,000 AVAX) [output.txt:1565]
The "sAVAX Rebalancer" (0x7A7b…a8C9) is a contract that helps users grow their leveraged Aave V3 sAVAX position. To do so it borrows WAVAX from Aave on behalf of the use…
Singularity dynBaseUSDCv3 Exploit — `totalAssets()` Inflation via a Mis-Configured (Fee-Tier-42 / Zero-Liquidity) Oracle Path
Loss · ~$413,132 — 413,132.022315 USDC drained from the vault's reserves, plus ~31,174 residual…
PermissionedDynaVault (deployed as dynBaseUSDCv3) is an ERC-4626-style multi-asset vault. Its totalAssets() sums the USDC value of every reserve token, pricing each non-…
Squid `SquidMulticall` Exploit — Arbitrary-Target `Default` Call Turns an Approved Multicall into a Universal `transferFrom` Proxy
Loss · 1.0 ETH (Binance-Peg ETH, 0x2170…33F8) drained from the victim in the reproduced transact…
1. SquidMulticall.run(Call[] calls) (contracts_router_SquidMulticall.sol#L18-L48) is a fully permissionless entry point: it iterates over a caller-supplied array of Call…
SubQuery (SQT) Exploit — Unprotected `Settings.setBatchAddress()` Role Hijack
Loss · 218,070,478.035174175990999309 SQT (~218.07M SQT) transferred to the attacker, plus a 0.1…
1. SubQuery routes every privileged-role lookup through a single Settings registry. The Staking contract decides "who is allowed to call me" by reading settings.getContr…
Thetanuts BTC/USD Vault Exploit — ERC4626-Style First-Depositor Share Rounding at `totalSupply() == 0`
Loss · 0.15177162 WBTC (15,177,162 sats) drained from the Thetanuts BTC/USD vault's pre-existing…
1. The Thetanuts BTC/USD covered-call vault at 0x80b8EEb3… was in a degenerate state: it held 15,179,557 sats of WBTC (output.txt:1592) while its totalSupply() was 0 (ou…
TTSwap Market: permissionless `initGood` + attacker-controlled ERC20 skews AMM accounting via `buyGood`/`payGood`
Loss · 5.098626217469779632 ETH (exact PoC / on-chain profit after 8 WETH Balancer repay)
1. Attacker CREATE-deploys a factory (nonce 0) that spawns a child exploit and a fake ERC20 good (spoofed transfer/balanceOf). 2. Child flash-loans 8 WETH from Balancer,…
Victim automation `execute()` missing auth drains yvWETH via Yearn withdrawal path
Loss · 429.210570004163139903 ETH (exact internal transfer / PoC profit)
1. Victim EOA holds ~384.667 yvWETH and grants max allowance to a personal automation at 0x143A…181A. 2. Automation exposes execute((uint8,bytes)[]) (selector 0x49650044…
xLOOT Staking Exploit — Duplicate NFT IDs in `redeem(uint256[])` Claim the Same Epoch Reward Repeatedly
Loss · 6.21 ETH total in the live incident; the extracted PoC nets 4.110409994732514492 ETH prof…
1. xLOOT stakers earn a weekly epoch reward. Each xLOOT NFT can claim a fixed earning-per-NFT (epn) for every epoch it has not yet redeemed. A per-NFT cursor xloot.nextR…
AlkemiEarn Exploit — Self-Liquidation Storage-Aliasing Collateral Duplication
Loss · 43.4540 ETH (~$43.45k+ at the time) drained from the AlkemiEarn WETH market
AlkemiEarn is a Compound-style money market (a hard fork of Compound v1 era code). Its liquidateBorrow (AlkemiEarnPublic.sol:3444) lets a liquidator repay an underwater…
ATM BlindBox predictable fallback RNG — attacker evaluates settlement seed before calling `settle`
Loss · ~13,000,000 ATM (~$99,000) reported; single attacker bet realized 285,000 ATM net profit…
BlindBox is a binary odd/even betting game attached to the ATM token. A user burns ATM to the 0x…dEaD address, the entry hook onBlindBoxEntry records a bet with the user…
BCE `scheduledDestruction` drain — token transfer hook burns LP reserve tokens then `sync()`s the pair
Loss · ~800,000 USDT (BCE/USDT pair drained to 259,506 wei of USDT; attacker realizes ~680,000 U…
BCE is an ERC-20 with a deflationary "scheduled destruction" mechanism: every sell into the BCE/USDT PancakeSwap pair adds value per 10 / 100 BCE to a global scheduledDe…
Curve LlamaLend (Inverse Finance sDOLA market) Exploit — Oracle / Band Manipulation Mass-Liquidation
Loss · ~$240,000 — extracted as 227,325.57 DOLA + 6.94 WETH
Curve LlamaLend is a lending market where collateral is continuously, automatically "soft-liquidated" inside a specialised AMM (LLAMMA) as the collateral price falls: as…
DayContract / Polarx — Spot Manip + Rigid Principal Guarantee
Loss · ~$10.6K attacker profit; ~$29.7K protocol insolvency
DayContract.deposit converts USDT → LP via Pancake spot reserves (no TWAP). withdraw always calls vault.settlePrincipal(user, fullPrincipal, 0), and the vault’s _ensureU…
EST / BNBDeposit Exploit — `skim()`-Fed Proportional Reward Drain + AMM Reserve Manipulation
Loss · 150.16 WBNB (~150.2 WBNB per the incident header) — the entire WBNB reserve of the EST/WB…
BNBDeposit is a referral/LP-staking contract for the EST token. When a user transfers exactly 1 EST to it, the EST token calls back BNBDeposit.onTokenReceived(), which p…
InfinitySix — Stale 1-min TWAP + Instant Referral Bonus Over-Mint
Loss · ~$273.8K USDT attacker profit (PoC net ~$277.2K without flash fees)
invest() immediately credits the sponsor with directBonus += 5% of the invest amount. withdraw() pays that USDT-denominated bonus in i6 tokens priced by twapPrice, but u…
Linea TokenBridge upgrade — permissionless reinitialization drains locks
Replacing an inherited initializer changes the storage layout. The live bridge appears uninitialized, letting an arbitrary caller become admin, install an attacker messa…
Movie Token (MT) double-count burn — BSC Mar 2026 ~$242K
UntaggedLoss · ~$242K (~381.7 WBNB)
Myriad CLOB — free YES tokens when cross-market `priceSum > ONE`
Untagged1. Cross-market match requires only priceSum >= ONE, not equality. 2. Maker notionals sum with round-down; taker pays max(0, fill - notionalSoFar). 3. When priceSum > ON…
Old CheckoutPool Bridge Operator (`_ALLOW_ALL_`) — permissionless bridge() routed an ERC-4337 paymaster into draining CheckoutPool's USDC excess
Loss · 85,730 USDC (85,729 from CheckoutPool._POOL_EXCESS_ + 1 USDC held by the checkout)
CheckoutPool is an ERC-4337 (account abstraction) payments pool: users register a "checkout" (a desired on-chain payment, e.g. pay 85,730 USDC to a recipient), lock up f…
Parallel 3.1 — processSurplus always reverts for managed collateral
Untagged1. Managed collateral lives on an external manager/strategy, never on the diamond. 2. getCollateralSurplus correctly uses manager.totalAssets(). 3. processSurplus self-s…
Revamp referral-reward drain — a self-referral that pays contributors out of existing pool BNB
Loss · 2.99 BNB (3.2078 BNB was the contract's entire native balance; ~2.9898 BNB is net attacke…
Revamp is a "revamp" / contribution protocol on BSC. Anyone can pay a listing fee to register an ERC-20, after which users call revamp(token, tokenAmount, referral) to s…
Sablier Bob Escrow — Adapter vault `_userWstETH` not cleared after redemption enables theft of other users' funds
Untagged1. Adapter vaults track each user's staked amount in _userWstETH. 2. On redeem, shares are burned and WETH is paid from calculateAmountToTransferWithYield — but _userWst…
Sablier Bob Escrow — Circular slippage protection in `SablierLidoAdapter::_wstETHToWeth` enables sandwich attacks
1. _wstETHToWeth sets minEthOut from Curve get_dy (current reserves). 2. exchange reads the same reserves — so a sandwich that depresses the pool makes both quote and sw…
StakeOnMe JAKE owner-wrapper reserve asymmetry — public owner-privileged mint vs. burn pays out against an inflated ETH reserve
Loss · 0.28 ETH (≈ 0.2793 ETH net to attacker; 1.919 ETH drained from the wrapper pool)
The JAKE meToken (0x277697FA…, a Bancor-style bonding-curve token) is governed by an unverified public contract at 0x237d…4b3f that the meToken reports as its owner() [o…
Univ3CollateralToken — Uni V3 position counted as collateral for every vault owned by the same minter
Loss · ~57,000 USD (USDC + USDC.e drained from the USDI reserve)
Univ3CollateralToken is the Uni-V3-position collateral adapter for a lending system (USDI / VaultController). When a user deposits a Uni V3 NFT into a vault, the contrac…
Venus (vTHE) Exploit — Donation-Inflated Exchange Rate + `borrowBehalf` Drains a Victim's Pre-Approved Delegate
Loss · 913,858.26 CAKE + 1,972.53 WBNB borrowed onto the victim's account and walked off by the…
Venus is a Compound-V2 fork. A vToken's collateral value is vTokenBalance × exchangeRate × price × LTV, and the exchange rate is computed as
VTSwapHook reserve/fee accounting divergence — Uniswap V4 custom-curve hook books full specified amount into reserves while pricing output on the fee-reduced input
Loss · 4,507,034.03 vATH + 2,007,935.14 ATH (per @KeyInfo)
VTSwapHook is an Aethir-style vesting-token (VT) swap pool built as a Uniswap V4 custom-curve hook (beforeSwapReturnDelta = true). Instead of using V4's concentrated-liq…
Whalebit Oracle Manipulation Exploit — Spot-Priced Level Staking Round-Trips a Manipulable Algebra Pool
Loss · 9,745.17 CES net intra-transaction profit (150,701.56 − 140,956.39 CES), drained out of W…
1. Whalebit sells fixed-size "levels". A user calls staking.deposit(level) and pays a fixed CES sticker amount for that level (level 12 = 6,426.84 CES, returned by level…
WUKONG Staking — classical reentrancy in `unstake()` drains pooled LP
Loss · ~57.68 BNB (~$37.7K) on the main tx (attacker EOA net gain); a second tx drained ~$18K
StakingUpgradeableV10.unstake() returns the withdrawer's BNB with a raw payable(msg.sender).call{value: bnbReceived}("") before it closes the position (isStaking = false…
Xocolatl AccountLiquidator — arbitrary caller-supplied HouseOfReserve zeroes the liquidation cost
Loss · 3.25 cbETH + 0.22 WETH (≈$11.2k at the time)
Xocolatl is an over-collateralized CDP system on Base: users deposit cbETH/WETH into a HouseOfReserve, receive a minted (backed) token as debt, and can be liquidated thr…
FoomCash / FOOM Lottery — Groth16 verifier with `gamma == delta` lets anyone forge proofs
Loss · 19,695,576,757,802.19 FOOM (~$1.3M) — the FOOM Lottery pool drained to dust in one tx
1. FoomCash's FoomLottery is a Tornado-style shielded pool: you play() to deposit FOOM behind a commitment, and later collect() a reward by presenting a Groth16 zero-kno…
LAXO Token Exploit — Uncompensated Pool-Side Burn on Every Sell Breaks `x·y = k`
Loss · ~137,320 USDT (BSC-USD) drained from the LAXO/USDT PancakeSwap pair
LAXOToken is a deflationary "tax token." Whenever someone sells (transfers LAXO to the PancakeSwap pair), its _transfer override doesn't just tax the seller — it burns u…
Moonwell cbETH Oracle Incident — Mispriced Collateral Enables Near-Free Liquidation
Loss · ~$1.78M protocol-wide bad debt (cbETH $1.03M, WETH $479K, USDC $233K, EURC, cbBTC, cbXRP,…
Moonwell (a Compound-v2 fork on Base) values collateral and debt for liquidations through its ChainlinkOracle. For cbETH that oracle reads a ChainlinkOEVWrapper, which i…
XDK Exploit — Sell-Path "Recycle" Removes XDK from the Live Pair and `sync()`s
Loss · ~6.84 WBNB — 6.840316534082275362 WBNB (~$3–4K) forwarded to the attacker EOA, sourced fr…
1. XDK is a fee-on-transfer "deflationary + dividend" token on BSC. Its uniswapV2Pair is the live XDK/GPC PancakeSwap pair (GPC, ticker for the AMMToken contract, is the…
2026-01 Sparkle! (SPRK) Tobin-tax self-transfer inflation
UntaggedLoss · ~$14.6K (alerter); PoC ~4.5 ETH net at attack-block reserve
FutureSwap Perpetual Drain — Fee Unit-Mismatch (`addFee` token-units interpreted as bps/share)
Loss · ~394,742.852305 USDC.e net attacker profit; victim drained of 197,436.748947 USDC.e of st…
FutureSwap is a perpetual-swap engine. A user calls changePosition(deltaAsset, deltaStable, stableBound) to open/close/resize a position; the engine swaps the asset leg…
Majority Protocol — free cross-game participation via unbound questionId
UntaggedcommitReaction only checks the caller joined _gameId, then forwards an arbitrary _questionId to the prompt strategy. Reactions are stored by questionId alone, so a free-…
Majority Protocol — multi assertResults causes bond loss for all but first
UntaggedassertResults is permissionless and accepts multiple bonds for the same sessionId. The first successful recordResults fills winners[sessionId]; the second reverts Winner…
Majority Protocol — re-join after leave permanently locks second entry fee
UntaggedAfter leaveRescheduledGame sets hasRefunded[gameId][player]=true, _payEntryFee on re-join never clears that flag. When the game is later cancelled, refundCancelledGame r…
Majority Protocol — refundCancelledGame missing join check
UntaggedSessionManager.refundCancelledGame only checks that the game is Cancelled, then refunds ticketPrice to msg.sender without verifying contestants[gameId][msg.sender]. An a…
Majority Protocol — start without ranked rewards locks prize pool
UntaggedFixedRanksReward.setRankedRewards (and ProportionalToXPReward.setNumberOfWinners) require Created state, but the game can start and conclude without them. claimRewards t…
Majority Protocol — start without XPTiers yields zero unclaimable rewards
UntaggedsetXPTiers is only allowed in Created, but the game can start without tiers. XP computation yields 0; ProportionalToXPReward then produces zero rewards and _distributeRe…
Makina Finance Exploit — Self-Referential AUM Oracle Manipulation via Permissionless Re-Accounting
Loss · ~$5.1M USDC drained from the DUSD/USDC pool (PoC reproduces $4,304,016 net profit over tw…
Makina is an on-chain asset-management vault. Users deposit USDC and receive DUSD (the MachineShare token). DUSD's "fair value" is the vault NAV per share: lastTotalAum…
MT Token Exploit — Fee-on-Transfer Overcharge Drains the AMM Pair via `skim()`+`sync()`
Loss · ~36,995.24 USDT net pool loss (gross USDT pulled from pair: ~226,722.24 USDT, the rest re…
MetaverseToken (MT) is a fee-on-transfer ERC20. On a normal transfer it takes a 5% fee (transactFeeValue = amount × 5 / 100) and is supposed to split that 5% among three…
PRXVT Staking Exploit — Transferable Reward-Receipt Token Resets `userRewardPerTokenPaid`
Loss · ~32.8 ETH (drain of the PRXVT staking reward reserve; reward reserve at the fork block ≈…
PRXVTStaking is a Synthetix-style staking contract whose receipt token stPRXVT is a plain, freely-transferable OpenZeppelin ERC20 (the contract is ERC20). Rewards are ac…
Statusl — bypass stake lock via leave + migrateToVault
Untagged1. Stake with a multi-year lock for max multiplier. 2. leave() zeros stakedBalance but does not permanently ban the vault as a migrate target. 3. An empty vault migrates…
Statusl — global MP cap broken on unstake causes permanent DoS
Untagged1. Protocol assumes totalMPAccrued totalMaxMP.
SynapLogic Exploit — Uncapped Cumulative Refunds in the Token Sale `buy` / `swap` Path
Loss · ~27.65 ETH (ETH attack) + ~3,450 USDC (USDC attack) — entire sale-contract balances; a th…
The SynapLogic presale lets a buyer purchase the project token while nominating a list of referral / refund recipients, each receiving some percentage of the buyer's own…
Truebit Exploit — Inverted `getPurchasePrice` Lets Anyone Buy TRU For Free, Then Sell For ETH
Loss · 8,539.41 ETH drained from the bonding-curve pool (the PoC starts with 1 ETH and ends with…
Truebit's bonding-curve pool prices TRU purchases with a function getPurchasePrice(amount) whose arithmetic is inverted: instead of returning numerator / denominator, it…
AmpleEarn — unrestricted router allows unauthorized merkle root setting
UntaggedRouter batchSetMerkleRootsStrict has no auth; vault setMerkleRoots authorizes msg.sender, which is the router when not routed through EVC
Monolith — free-debt rounding allows unbacked borrow
Untagged1. Free-debt share math rounds personal debt up. 2. Redeem + debase loops inflate freeShares / freeDebt; residual shares can survive after the last free-debt wei is repa…
Panoptic — commission fees can always be bypassed
Untagged1. settleBurn takes commission = min(premiumFee, notionalFee). 2. _settleOptions passes long=short=amm=0 so notionalFee = 0 → commission 0. 3. If realizedPremium == 0 th…
Panoptic — cross-contract reentrancy converts phantom shares to real shares
Untagged1. Liquidation delegates type(uint248).max phantom shares on ct0 and ct1. 2. ct0.settleLiquidation refunds ETH to liquidator before ct1 is revoked. 3. Reentrant transfer…
Ribbon Finance MarginPool — corrupted oToken expiry prices via pricer proxy takeover
Loss · ~$2.7M
Legacy Ribbon/Opyn-style MarginPool held collateral for cash-secured call oTokens that expired OTM. The attacker temporarily took ownership of multiple asset pricer prox…
yETH Weighted-StableSwap Exploit — Invariant Rounding Drift Mints Unbacked LP
Loss · ~$9M — the pool's entire LSD reserve: ~2,587 ETH-equivalent across 8 liquid-staking tokens
The yETH pool is a Curve-style weighted stableswap whose invariant D (a.k.a. supply) is solved iteratively in _calc_supply() and whose per-asset terms use a rounded _pow…
Balancer V2 Exploit — ComposableStablePool Rounding-Error Drain via Rate-Scaled `_upscale`/`_downscale`
Loss · ~$120M total across many affected ComposableStablePools (BlockSec/SlowMist figures). This…
Balancer V2 prices every pool in 18-decimal fixed point. To do so it upscales raw token amounts by a per-token scalingFactor, runs StableMath on the scaled values, then…
DRLVaultV3 Exploit — Self-Referential Slippage Lets a Manipulated Pool Set Its Own "Minimum Out"
Loss · ~$100,000 — the vault's full 100,000 USDC balance, swapped for 0.0001205 WETH (≈ $0.43)
DRLVaultV3 is an automated Uniswap-V3 liquidity-management vault. To rebalance, it swaps USDC into WETH via swapToWETH(). That function is:
Megapot — Attacker can steal JackpotTicketNFTs from JackpotBridgeManager
Untagged_bridgeFunds calls _bridgeDetails.to with attacker-supplied calldata after optionally approving USDC. Pointing to at the ticket NFT and data at safeTransferFrom(bridge →…
Megapot — LP pool cap may be exceeded on drawing settlement
UntaggedprocessDrawingSettlement computes newLPValue without the same pool-cap clamp used on deposits
Megapot — Unoptimized subset matches counting exceeds Base tx gas limit
Untagged_countSubsetMatches regenerates subsets for every bonusball. At bonusballMax=129 the settlement callback measures ~25.8M gas and exceeds Base's 25M per-tx limit, so Pyth…
Moonwell Exploit — Corrupted wrsETH Oracle ⇒ Borrow ~$88K Against ~$0.07 of Collateral
Loss · ~$1M total across Moonwell markets; the reproduced single transaction nets 24.92 WETH ≈ $…
Moonwell prices its wrsETH collateral with a ChainlinkCompositeOracle that multiplies an ETH/USD feed by a "wrsETH→ETH exchange-rate" feed (ChainlinkCompositeOracle.sol:…
stNXM — attacker profits by manipulating Uniswap liquidity via slot0
UntaggeddexBalances reads Uniswap V3 slot0 spot price to value LP inside totalAssets
Accountable — `AccountableOpenTerm` interest cannot be repaid once principal hits zero
1. Interest accrues virtually via _scaleFactor / scaleFactor. 2. repay() only reduces outstandingPrincipal; excess for interest is optional. 3. When principal reaches ze…
Accountable — Cancelling redeem requests permanently blocks the withdrawal queue
1. Redeem requests sit in a FIFO queue keyed by nextRequestId (head). 2. Cancelling a request fully deletes the entry (controller = address(0)) without advancing the hea…
BaseSwapCallback Exploit — Public `uniswapV3SwapCallback` Approval Drain
Loss · ~55.51 WETH (~$220K) drained from a single approver
An unverified Base router-like contract exposes uniswapV3SwapCallback(int256,int256,bytes) without verifying that msg.sender is a real Uniswap V3 pool created by a trust…
BOB Staking — Bonuses obtainable without proper locking
1. First stake with lockPeriod = 0 sets unlockTimestamp = now and stores lockPeriod = 0. 2. Second stake with a long lock period still passes the consistency check (guar…
BOB Staking — Delegating to address(0) empties contract via alterGovernanceDelegatee
1. First non-zero delegation moves the staker's tokens contract → surrogate. 2. Setting delegatee to address(0) is allowed; tokens move to a zero surrogate. 3. Re-delega…
BOB Staking — instantWithdraw does not transfer amountForContract
1. Delegated stake lives in a DelegationSurrogate. 2. instantWithdraw pulls only _amountForUser from the surrogate. 3. _amountForContract (penalty) is never transferred…
Centrifuge v3.1 — pool managers steal other pools pending deposits
UntaggedSpoke.requestCallback uses current requestManager without binding to the manager that created the request
Hybra Finance — Assets deposited before calculating shares to mint
1. deposit first moves HYBR into the voting escrow (increasing totalAssets). 2. Then shares = calculateShares(amount) uses the post-deposit total. 3. At 1:1 with 100 alr…
MIM Spell ("MIMSpell3") Exploit — Collateral-Free MIM Mint from Privileged Cauldrons
Loss · ~$1.7M — 1,793,766 MIM minted with no collateral, exited as 389.75 WETH
Abracadabra's CauldronV4 is the standard MIM lending engine: you cook() a sequence of actions — add collateral, borrow, repay, etc. A normal ACTION_BORROW sets a flag so…
Remora — `buyTokenOCP` signatures reusable forever (missing nonce)
1. buyTokenOCP verifies an EIP-712-style BuyToken(investor, token, amount) signature and skips on-chain payment. 2. The hash omits a nonce and nothing marks the digest a…
Remora — div-before-mul in `FiveFiftyRule::_updateEntityAllowance` exceeds caps
1. Allowance updates use (REMORA_PERCENT_DENOMINATOR / equity) amount. 2. Integer division truncates first → delta is smaller than DENOM amount / equity. 3. On the reduc…
Remora — resolveUser lock migration can be griefed to extend lock duration
1. resolveUser migrates locks by appending old locks after any locks already on newAddress. 2. availableTokens stops at the first unexpired entry. 3. A frontrun transfer…
Remora — unrestricted `SignatureValidator::setAllowlist` enables free `buyTokenOCP`
1. SignatureValidator.setAllowlist is external with no restricted / onlyOwner guard. 2. TokenBank inherits it, so anyone can point the bank at a MaliciousAllowlist whose…
Securitize DSToken — unapproved `transferFrom` theft
StandardToken.transferFrom calls its transfer primitive directly and never checks the owner's allowance for msg.sender. An arbitrary investor can therefore debit any oth…
Sequence — partial session-signature replay / frontrun (H-02)
1. Calls.execute bumps the nonce, validates the session signature, then runs calls. 2. A later call with BEHAVIOR_REVERT_ON_ERROR reverts the entire transaction → nonce…
Sharwa Finance Exploit — Margin Position Closed Against an Attacker-Manipulated Spot Pool (No Slippage Bound)
Loss · ~$146,000 total (real attack, multiple position cycles). This PoC reproduces one cycle, n…
Sharwa Finance is a margin-trading protocol. To open a "long WBTC" position the protocol borrows USDC from its LiquidityPool and swaps it for WBTC on Uniswap V3, sizing…
Sorella L2 Angstrom — All rewards can be stolen via incorrect active liquidity at boundary ticks
1. When the current tick is an exact multiple of tick spacing at an upper liquidity bound t1, zero-for-one iteration should apply liquidityNet[t1] first. 2. _advanceToNe…
Strata Tranches — donation-prevention gamed → withdrawals stuck
UntaggedDonate to Strategy before first deposit → first mint is 1 wei of shares. Later large deposits still leave totalSupply < MIN_SHARES. Every withdraw reverts; capital stuck.
Strata Tranches — sUSDe withdrawers always incur a loss (inverted CDO params)
Untagged1. Withdraw of 100 sUSDe (worth 150 USDe at 1.5 rate) burns 150 JRT shares. 2. Tranche passes (baseAssets, tokenAssets) but CDO expects (tokenAmount, baseAssets). 3. Str…
Strata Tranches — withdrawal active requests DoS'd by malicious users
UntaggedAnyone can call transfer(..., victim, 1 wei) and inflate the victim's request array. finalize iterates all entries → OOG after ~35k spam (shown via sample×extrapolate).
TokenHolder / BorrowerOperationsV6 Exploit — Privileged-Role Confused-Deputy Drain via `sell()`'s Arbitrary Call
Loss · 20 WBNB drained from the protocol's TokenHolder vault per sell() call (attacker netted 19…
TokenHolder is a small lending vault that holds WBNB and lends it out via privilegedLoan() — a function correctly guarded by onlyBorrowerRouter, so only an address holdi…
Ammplify — H-10: `subtreeBorrowedX/Y` is node-only (makers underpaid)
Untagged1. Child holds large subtreeBorrowed; parent holds small own borrow. 2. Fee charge on parent adds only parent.subtreeBorrowedX (node-only). 3. Child mass ignored → fees…
Ammplify — H-11: Segment-split geometric-mean borrow overstates taker fees
Untagged1. Full-range borrow at one GM tick is the economically intended base. 2. Segment tree stores liq in multiple nodes; each uses its own GM. 3. Sum of segment borrows ≫ fu…
Ammplify — H-3: Pool liquidity vs node liquidity mismatch from wrong `PoolWalker.settle` route
1. WalkerLib.modify marks nodes using high index treeTick(highTick) - 1. 2. PoolWalker.settle walks high index treeTick(highTick) (one higher). 3. Settlement skips the c…
Ammplify — H-5: Borrow fee uses APY as per-second rate (extreme overcharge)
Untagged1. Smooth rate curve returns an annual rate (APY) in Q64.64. 2. chargeTrueFeeRate does takerRateX64 = timeDiff * calculateRateX64(util) with no / 365 days. 3. Even 1 sec…
Ammplify — H-6: First-deposit share inflation steals compounded maker deposits
Untagged1. Each compounded segment acts as a vault with shares = liq * totalShares / totalLiq (floor). 2. Attacker seeds min liquidity, donates, shrinks to 1 share, donates agai…
Ammplify — H-7: `collectFees` re-targets original `asset.liq` after `adjustMaker`
Untagged1. newMaker stores asset.liq = 300e18. 2. adjustMaker sets live liq to 100e18 but leaves asset.liq unchanged. 3. collectFees re-targets to asset.liq → position snaps bac…
Ammplify — H-8: Uninitialized Uniswap ticks inflate `getInsideFees` (funds stuck)
Untagged1. Open maker while ticks uninitialized and price inside range. 2. Snapshot stores feeGrowthInside = feeGrowthGlobal (inflated). 3. Settle initializes ticks; later getIn…
Ammplify — H-9: Parent borrow marks sibling but settle skips sibling mint
Untagged1. Taker demand on a child forces borrow from parent. 2. Sibling also receives preBorrow (parent liq = both children). 3. Settle walks only the op route (child+parent),…
Ammplify maker spot-price manipulation — AuditVault 63167
Maker deposits value liquidity using a manipulable Uniswap spot price.
Ammplify malicious pool address — AuditVault 63179
newMaker accepts an attacker-controlled pool and transfers protocol token accounting to it.
H-1: notifyUnsubscribe gas underestimation leaves phantom gauge liquidity
UntaggedUniswap unsubscribes while Deli gauge keeps full position liquidity (phantom dilution)
H-4: Finalize-window auto-vote change manipulates past epoch
UntaggedPost-epoch auto-vote + live balance counted at finalize; WETH allocation manipulated
Kame Aggregator Exploit — Unvalidated `executor.call()` in `swap()` Drains User Approvals
Loss · 18,167.88 USD (USDC, 6 decimals — pulled from one approving user)
AggregationRouter is a DEX-aggregator router on Sei. To execute a swap it forwards the user's tokens to "an executor" and then performs a single, fully attacker-supplied…
Licredity — decreaseDebtShare bypasses interest accrual
1. Interest accrues only in unlock / swap / LP add-remove paths. 2. decreaseDebtShare is allowed outside unlock because it only reduces debt. 3. It burns fullMulDivUp(de…
Licredity — proxy-based self-liquidation creates bad debt for lenders
1. Licredity.seize tries to stop an owner from profitably self-liquidating with if (position.owner == msg.sender) revert CannotSeizeOwnPosition(). 2. This checks only th…
Licredity — self-triggered afterSwap back-run enables LP fee farming
1. When price hits/goes below 1, _afterSwap auto back-runs a reverse swap to restore parity. 2. That back-run pays swap fees to LPs. 3. A dominant LP around 1 captures n…
Licredity — swap-and-pop without index fix-up corrupts Position fungibles
1. Position tracks fungibles in an array and a fungibleStates mapping (1-based index + balance). 2. On full remove, the code swap-and-pops the array but never updates th…
MetaMask — TotalBalanceEnforcer validation bypass with state-modifying enforcers
UntaggedafterAllHook early-returns when shared BalanceTracker was cleaned by a prior TotalBalance enforcer; later enforcers skip validation after mid-chain state changes
NGP Token Exploit — Sell-Fee Burns NGP *Out of the Pair* and `sync()`s, Collapsing the AMM Reserve
Loss · ~493,467 USDT in this single simulated transaction (the campaign drained ~2M USDT total a…
NGP is a fee-on-transfer token. On every sell (any transfer where to == mainPair), its _update hook does something a token must never do: it moves the treasury fee + rew…
Super DCA — H-4: Bucket rewards wiped by stake/unstake before accrue
UntaggedAfter rewards accrue on a bucket, any stake/unstake resets lastRewardIndex to current rewardIndex. Subsequent accrueReward sees delta 0 → paid = 0.
0x8d2e Exploit — Permissionless `uniswapV3SwapCallback` Drains the Contract's USDC
Loss · 40,000 USDC (≈ $40k) — the entire USDC balance of the victim contract
0x8d2e is some kind of trading/router contract that exposes a Uniswap-V3-style uniswapV3SwapCallback(int256 amount0Delta, int256 amount1Delta, bytes data). In a real Uni…
0xf340 VRF-Wrapper Exploit — Permissionless `initVRF()` Hijacks the LINK Payment Recipient
Loss · ~$4,000 — 160 LINK drained, swapped to 0.837736523415338256 ETH
0xf340 is a thin Chainlink VRF wrapper (a TransparentUpgradeableProxy delegating to implementation 0xd92A9110…). It holds a balance of LINK and, when randomness is reque…
ABCCApp Exploit — Permissionless `addFixedDay()` Vesting Time-Warp Drains the DDDD Reward Reserve
Loss · ~10,062 BUSD profit per cycle (≈ the protocol's DDDD reserve, sourced from prior deposito…
ABCCApp is a "deposit-and-earn" / referral scheme. A user deposits BUSD; the contract:
AutoPooledTradingBot double-withdrawal — withdrawInvestment pays out from deposits without burning shares, so emergencyWithdrawAll pays the same position twice
Loss · 0.15198 ETH on-chain (PoC reproduces 0.152158266800401203 ETH net profit after flash-swap…
AutoPooledTradingBot is an ETH "auto-trading pool" that issues share tokens on deposit() and lets users exit through one of two paths: withdrawInvestment() (an "earnings…
BaseCallback `0x8d2e…` Exploit — Unauthenticated `uniswapV3SwapCallback` Self-Transfer
Loss · 40,000 USDC (~$40K) held by the vulnerable contract
Unlike Q12 (approval transferFrom drain), this victim held the USDC itself. Its uniswapV3SwapCallback accepts a call from any msg.sender and, for amount0Delta > 0, does:
BaseSwapperUniswapV3 public swap drains its own token balance — arbitrary public access + full-balance refund to caller-chosen recipient
Loss · ~1,847.33 USD (472,997,613,026,749,247,557,538 wei of a deflationary victim token, draine…
BaseSwapperUniswapV3 is an admin-owned wrapper around the Uniswap V3 ISwapRouter. Its admin registers token paths via setPath() and pre-approves the router for type(uint…
Bebop JAM Settlement Exploit — Signature-Bypass + Unconstrained Interactions Drain Stale Approvals
Loss · 20,069.560783 USDC (~$20.1K) drained from two pre-approving users; campaign total ≈ $21K
JamSettlement is the on-chain settlement engine for Bebop's "JAM" RFQ trading. A solver calls settle(order, signature, interactions, hooksData, balanceRecipient); the co…
Bebop JamSettlement self-taker arbitrary-interaction drain — caller-supplied `transferFrom` calldata executed by the settlement contract against accounts that approved it
Loss · 3,875.46 USD (1,000 USDC + 901.467 uXRP)
Bebop's JamSettlement.settle(...) is meant to atomically execute a signed swap: a taker's signed JamOrder authorizes pulling the taker's sell tokens, then the solver pas…
Beefy ZapRouter arbitrary route execution — arbitrary `call()` spent victim allowances via `transferFrom`
Loss · ~6,584.95 USD (2,782.482 vault-A mooTokens + 2,779.111 vault-B mooTokens stolen from two…
Beefy's BeefyZapRouter is a generic "zap" router: a user deposits input tokens, the router runs an arbitrary caller-supplied list of Steps (each a low-level target.call(…
BSC "DD" initcode-token drain — unverified victim exposes arbitrary token-path swap using its own WBNB
Loss · ~0.913 WBNB in the PoC (victim drained from 912.716e15 WBNB to 2,486,728 wei WBNB). On-ch…
The victim contract 0x0B0d…c4Da exposes a public function (selector 0xdc0b3665) that takes a token pair and an amountIn and performs two PancakeSwap swapExactTokensForTo…
Caller-supplied ControlTower grants migrator power — AuditVault synthetic reduction
This bug report is about a vulnerability found in a contract called the "2025-08-usg-tangent-judging" contract. The vulnerability was discovered by multiple individuals…
Coinbase Fee-Account Drain — Confused-Deputy via 0x Settler `BASIC` Arbitrary Call
Loss · ~$300,000 total across multiple tokens. This PoC reproduces one leg: 105,493.58 ANDY drai…
The 0x Settler is a swap router that, by design, can be told to perform a raw external call to any address through its BASIC action (selector 0x38c9c147). The Settler is…
D3X AI Exploit — Proxy `exchange()` Prices D3XAT From A Manipulable PancakeSwap Spot Reserve
Loss · 190 BNB (≈ 135,919 USDT net intra-transaction profit, per the balance log)
D3X runs a small in-house "swap desk": a TransparentUpgradeableProxy exposing exchange(fromToken, toToken, amount) (first call: output.txt:1739). When you sell D3XAT int…
Equilibria (VaultEPendle) — reward debt not updated on ERC20 share transfer, draining native-ETH rewards via fresh receivers
Loss · ~62,661.57 USD (≈ 13.29 ETH drained in this reproduction; on-chain incident per @KeyInfo)
Equilibria's VaultEPendle ("stk-ePendle") is a single-asset auto-compounding vault that wraps ePendle (Equilibria's 1:1 escrowed Pendle) and distributes extra EQB / xEQB…
EverValueCoin (EVA) Exploit — Stale-Price Orderbook Settlement Arbitraged Against a Live AMM
Loss · 1.19331 WBTC drained from the order book (DeFiHackLabs header: ~$100k; ≈ $130k at the ~$1…
OrderBookFactory is a custom on-chain limit order book. When a new order matches a resting order, it settles instantly and atomically at the resting order's stored price…
Fake staking pool is accepted by stakeNxm — AuditVault synthetic reduction
This bug report discusses a vulnerability found in the stNXM contract, which allows the contract owner to steal funds from the contract. The bug was found by multiple in…
Grizzifi Exploit — Sybil Milestone-Reward Farming via Self-Referral Chain
Loss · ~$61,000 USD on-chain (BSC-USD). The minimal PoC here nets +1,000 BSC-USD per round (600…
Grizzifi is a USDT (BSC-USD) staking / MLM-style protocol. Besides daily staking yield, it pays "team milestone" bonuses: when the count of people in your downline ("tea…
GTE — burn over-estimates LP distribution when launchpad fees accrued
Untagged1. Accrued launchpad fees sit in pair balances but are excluded from reserves. 2. mint prices LP against reserves; burn pays out against full balances. 3. Mint + burn ca…
GTE — Distributor addRewards with fake quoteToken drains real rewards
Untagged1. addRewards(launch, fake, 0, amount) accepts any token1. 2. Fake transferFrom succeeds; pendingQuoteRewards inflates. 3. Claims pay the registered real quote token. 4.…
GTE — DOS graduation via 1-wei donation + sync
Untagged1. Donate 1 wei quote to empty pair and sync(). 2. Reserves become one-sided (0, >0). 3. UniswapV2Library.quote requires both reserves > 0 → reverts. 4. HARM: graduat…
GTE — free LP mint when accrued launchpad fees are non-zero
Untagged1. Reserves = balances − fees. 2. mint without transfer sees amount = fees → free LP. 3. Burn cashes out the free share of pool assets. 4. HARM: both tokens stolen with…
GTE — Launchpad pairFor CREATE2 salt mismatches factory
Untagged1. Factory salt = keccak(token0, token1, launchpadLp, feeDistributor). 2. pairFor salt = keccak(token0, token1) only. 3. If createPair already exists, try/catch leaves t…
GTE — swap drains pair via phantom amountIn from launchpad fees
Untagged1. Reserves exclude accrued launchpad fees; balances include them. 2. amountIn is inferred as balance - (reserve - amountOut). 3. Taking amountOut ≈ fee with no transfer…
Hexotic (HEX-OTC) Exploit — Mispriced OTC Orders Arbitraged Against Uniswap-V3 Spot
Loss · ~$500 (the over-paid ETH escrowed in two mispriced orders). In this fork run the attacker…
HEXOTC is a tiny peer-to-peer OTC escrow for swapping ETH ⇄ HEX. A maker can lock ETH in the contract (an "ETH-escrowed" offer, escrowType == 1) declaring how much HEX t…
Hiding a staked NFT inflates share ownership — AuditVault synthetic reduction
Summary: The bug report describes a vulnerability in the stNXM smart contract that allows the owner to manipulate the value of the staked Nexus NFT without withdrawing i…
LUXERA (XERA) Exploit — Dangling Infinite Approval to Multicall3 Drained via `aggregate3`
Loss · ~$17K — 41.0347 WBNB drained from the XERA/WBNB PancakeSwap pair
The XERA token contract itself is a textbook OpenZeppelin-v5 ERC20 with fee/dividend extensions; its transferFrom/_spendAllowance are standard (ERC20.sol:154, ERC20.sol:…
MyCoinMaster missing-access-control on `buyBYAdmin` lets anyone mint MYC for free and drain the pool via `swap` — public function lacked an `onlyAdmin` guard present on every other privileged path
Loss · ~653.49 USD (653.63 USDT) — [output.txt:1594,1663,1672]
MyCoinMaster is a BNB-Chain token-sale / staking protocol where users normally buy the MYC token by paying either BNB or USDT. The "buy" path locks the purchased tokens…
Owner burns liquidity from an arbitrary NFT position — AuditVault synthetic reduction
This bug report discusses an issue found in the stNXM contract, where the owner is able to steal funds from the vault and the protocol is unable to recover them. The bug…
PDZ / "TB Build" Exploit — Spot-Price `getAmountsOut` Reward Inflation
Loss · 3.3 BNB (per PoC @KeyInfo)
The PDZ ecosystem has a "burn-to-earn" mechanic. A user calls TOKENbnb.burnToHolder(amount, _invitation): they give up amount PDZ tokens (which get sent to the dead addr…
Pendle Reflector — reflect() operated on Reflector-held balances using caller-supplied, unvalidated market and limit-router addresses
Loss · ~2,304.18 USD (Reflector's full balances of PT-mPendle-27MAR2025 and PT-stk-EPendle-27MAR…
Pendle's Reflector is a thin fronting contract whose only job is to take a blob of calldata, re-scale the input amount to whatever balance Reflector itself happens to ho…
PresaleV5 oracle manipulation — flash-loan spot-price (`slot0`) read by the presale pricing function let an attacker buy tokens cheap and sell them at fair price
Loss · 2.3157 ETH (attacker net profit)
PresaleV5 is an ETH/USDT-based token presale ("dynamic sale") whose token price is not a fixed schedule but is derived on-chain from a Uniswap V3 pool. The price functio…
RWf(x) undercollateralized underflow — AuditVault 63647
loadSwapState subtracts debt from collateral without handling an undercollateralized system.
Size Credit `LeverageUp` Exploit — Arbitrary External Call via `GenericRoute` Swap Drains User Approvals
Loss · ~$19.7k — 20,000 PT-wstUSR-25SEP2025 drained from one approving user
LeverageUp is a "one-click leverage" helper on top of the Size Credit lending market. To build a leveraged position it has to swap tokens, and it supports several swap b…
Size Credit FlashLoanLoopingV1_7 Generic-Route Arbitrary Call — third-party token allowance theft via caller-controlled `router.call(data)`
Loss · ~533 USD (540.576557 PT-wstUSR-25SEP2025 tokens stolen from one victim) [output.txt:1564-…
Size Credit's FlashLoanLoopingV1_7 is an Ownable zap contract that lets a user flash-loan from Aave, swap the borrowed token into collateral, deposit, and borrow in one…
Unverified Polygon swap router drained via fake Uniswap V3 pool — attacker-supplied pair/callback trusted without authentication
Loss · 3,131.106630910288079590 DAI (entire victim DAI balance)
0xd132…3B0bafF is an unverified Polygon contract exposing a swapSingleToken(address pair, address from, address token, bool zeroForOne, uint256 amount) selector that mim…
Unverified proxy `0x6f7a` drained via permissionless `rebalanceAndAddLiquidity` selector — anyone could push a victim's live token balance through its liquidity path
Loss · 7,630.46 USD reported (~0.25 WETH realized by the attacker on this fork) [output.txt:1539…
The victim contract 0x6f7a is a proxy that holds a treasury of DAI, WETH and FEI and, through its implementation, can "rebalance" its holdings into liquidity positions b…
WXC Token Exploit — Burn-From-Pool + `sync()` "Phantom Reserve" Drain
Loss · 37.55 WBNB net profit to the attacker (≈ the pool's honest WBNB liquidity, drained from t…
WXC is a sell-taxed, "deflationary" BEP-20. Its transfer logic treats a transfer to the LP pair as a sell, and as part of that path it burns the seller's net (post-tax)…
YuliAI Exploit — Buyback Priced off a Flash-Manipulated V3 Spot Price
Loss · ~$78,800 — 78,799.93 USDT drained from the YULIAI buyback contract
The contract at 0x8262…6282 is a YULIAI buyback desk: anyone can call sellToken(amount) to sell YULIAI to it, and it pays out USDT computed from the live YULIAI/USDT Pan…
Yuzu non-atomic updatePool sandwich — AuditVault 62757
A donation can be inserted before updatePool, changing the spot-derived pool value in the same transaction sequence.
AnyswapV4Router permit-fallback drain — trusting a non-reverting `permit()` on a token that does not enforce it
Loss · 200 WETH (amount modelled in the PoC; the on-chain attack tx drained a victim who had a s…
AnyswapV4Router is a cross-chain bridge router. Its anySwapOutUnderlyingWithPermit entry point is meant to take an EIP-2612 permit signature from a user, apply it on the…
Aragon — EarlyExecution proposals vulnerable to flashloan vote attacks
1. EarlyExecution mode executes a proposal as soon as a YES vote pushes it over the support threshold. 2. If the lock token is flashloanable/flashmintable, an attacker c…
Arcadia RebalancerSpot — Unvalidated `swapData` → Arbitrary `router.call`
Loss · ~$2.5–3.6M total (multi-tx; ~1203 ETH bridged). This PoC primary victim ≈ 197.72 WETH
Arcadia’s RebalancerSpot is an Asset Manager for user Accounts. Initiators call rebalance(account, …, swapData). When swapData is non-empty, SwapLogic._swapViaRouter dec…
BIFKN314 (ERC-314) flash-swap LP inflation — reserve snapshot taken after swap-out, before repayment, lets a dust `addLiquidity` mint pool-dominating LP shares
Loss · ~2,422.73 USD (91.15 AVAX profit, on-chain trace output.txt:1565)
BIFKN314Mintable is an ERC-314-style native/token pair that bundles a Uniswap-V2-like constant-product pool with a built-in flash swap: flashSwap() sends AVAX and the pa…
BoJ Leverage Market cbBTC reserve index inflation — flash-loan fee compounding against a near-empty aToken supply inflates the liquidity index to steal every listed asset
Loss · ~7,227.59 USD (mixed: WETH, USDC, AERO, MORPHO, DEGEN, VIRTUAL)
The BoJ Pool is an Aave-v3-derived lending market on Base branded around "Bank of Japan" leverage. Like upstream Aave v3, when a flash loan is repaid the LP portion of t…
Consensus accepts duplicated signers — AuditVault synthetic reduction
This bug report discusses a vulnerability found in the Mellow Flexible Vaults protocol, which was discovered by multiple individuals. The issue lies in the SignatureQueu…
Empty Set Reserve stale fixed-order drain — buying COMP below market from a hard-coded maker/taker price
Loss · ~$1,509.78 (≈ 0.4157 ETH extracted)
Empty Set Reserve (ESR) is a legacy Empty Set Dollar derivative contract that, among other things, runs a small on-chain OTC "order book." Each order is just a (price, a…
FeeManager miscalculates performance fees — AuditVault synthetic reduction
This bug report discusses an issue found in the performance fee calculation of the Mellow Flexible Vaults protocol. The current formula used in the FeeManager.calculateF…
FPC Token Exploit — Sell-Side `burnLpToken()` Drains the Pool's Own FPC Reserve
Loss · ~4.67M USDT (attacker net profit 4,671,608.07 USDT; reported headline ≈ $4.7M)
FPC is a "tax/deflation" token whose ERC-20 _update hook adds custom buy/sell logic. On a sell (any transfer into the FPC/USDT pair that the token classifies as a sell),…
GMX v1 Exploit — GLP Share-Price Manipulation via `globalShortAveragePrice`
Loss · ~$41M — GLP-pool reserves drained across 9 tokens (WETH, BTC/WBTC, USDC, USDe, LINK, UNI,…
GMX v1 prices its liquidity-provider token, GLP, off the Vault's Assets Under Management (AUM). For each non-stable token, AUM includes the aggregate unrealised PnL of a…
GTE CLOB — amend bypasses maxLimitsPerTx
Untagged1. postLimitOrder enforces maxLimitsPerTx via incrementLimitsPlaced. 2. amend to a new price creates a new book position without incrementing. 3. Attacker posts up to th…
Liquity V2 ActivePool `urgentRedemption` — permissionless extraction of collateral from shut-down undercollateralized troves at a +2% bonus
Loss · ~2,696.49 USD (1.0385 ETH per on-chain transaction) output.txt:1562
Liquity V2 lets each collateral branch (e.g. the sUSDe branch) be shut down in an emergency. When a branch is shut down the TroveManager opens a public urgentRedemption(…
Liquity V2 scrvUSD branch urgent-redemption arbitrage — permissionless cherry-picking of undercollateralized troves with a 2% bonus
Loss · ~$4,204.55 USD (net ETH profit 1.669775970301739864 ETH)
Liquity V2 lets a collateral branch be shut down when its total collateral ratio falls below the shutdown collateral ratio (SCR). Once shut down, normal borrowing and re…
Mellow Flexible Vaults — native token withdrawals permanently bricked
1. Protocol lists native token (0xEeee…eEEeE) as a supported asset. 2. Liquid-asset queries always call ERC20 balanceOf on the asset address. 3. Native sentinel has no c…
Mellow Flexible Vaults — protocol fee multi-accrual in submitReports
1. Each handleReport accrues protocol fees from last timestamp → now. 2. updateState only writes the timestamp when the asset is the base asset. 3. Non-base-first batch…
Mellow Flexible Vaults — RedeemQueue batch vs claim timestamp mismatch
1. Batch creation excludes the last request at/before the report timestamp (index--). 2. Claim eligibility still allows any request with ts ≤ priceTimestamp. 3. User2 cl…
MulticallWithETH Exploit — Arbitrary-Call `aggregate()` Drains an Unlimited USDC Approval
Loss · ~10,536.89 USDC (10,536,885,633,853,077,370,507 wei, 18-dec USDC on BSC)
MulticallWithETH is a generic, Multicall3-style batch executor. Its core function aggregate() loops over a caller-supplied list of (target, callData, value, allowFailure…
RANT Token Exploit — Self-Transfer Triggers Un-compensated LP Reserve Burn
Loss · ~311.48 BNB (~$190K at the time) drained from the RANT/WBNB PancakeSwap pair
RANTToken is a "deflationary + auto-burn" meme token. Its _transfer override has a special branch: when a non-pair, non-whitelisted address sends RANT to the token contr…
Redeem queue burns shares before charging fees — AuditVault synthetic reduction
This bug report discusses an issue found by a group of users regarding the redeem function in the RedeemQueue contract. When a user redeems their shares, the shares are…
Remora Pledge: `changeStablecoin` swaps the payment token's decimals without rescaling raw-unit accounting
UntaggedRemora Pledge: `pledge` spends a victim's stablecoin because it never checks `msg.sender == data.signer`
UntaggedRemora Pledge: `pricePerToken * numTokens` multiplies two `uint32`, so every pledge above ~$4,294 permanently reverts
UntaggedRemora Pledge: PaymentSettler can change its stablecoin but RemoraToken can't, permanently DoSing fee-bearing transfers
UntaggedRemora Pledge: removing a shared forwarder calls `deleteUser`, wiping `calculatedPayout` still owed to every other forwarding holder
UntaggedRemora Pledge: uint64 `calculatedPayout` overflows on high-decimal stablecoin payouts, permanently bricking claims
UntaggedResolv self-transfer reward theft — AuditVault 61872
Self-transfers credit both sender and recipient reward paths, doubling the reward.
Securitize OnRamp replay — signed transactions remain valid after use
executePreApprovedTransaction includes a nonce in the signed payload, but only increments the stored nonce. It never requires the supplied nonce to equal the current exp…
StakeDAO — [C-01] Missing extra reward per token update on deposit
UntaggedFirst user deposits and extra rewards are funded. Second user deposits a huge amount without the index updating first, then withdraws/claims — receives ~100k/100001 of r…
Stepp2p Exploit — Double-Refund via `modifySaleOrder` on an Already-Cancelled Order
Loss · ~$43.8K — 43,782.41 USDT (BSC-USD) drained from the Stepp2p escrow contract
Stepp2p is a simple P2P USDT escrow: a seller deposits USDT into a sale order and the contract holds it until a buyer purchases or the seller cancels. The accounting rec…
StrategyLlamaLendConvex share-accounting drain — a dust deposit minted strategy shares that redeemed for the strategy's entire Curve Lend position
Loss · 563.12 USDC (crvUSD-denominated drain of ~563 crvUSD from the strategy's Curve Lend / Con…
StrategyLlamaLendConvex is a Yearn V3 "tokenized strategy" that takes crvUSD as its asset and routes it into a Curve Lend vault (an ERC-4626), then stakes the resulting…
SuperRare Staking Exploit — Permissionless `updateMerkleRoot()` + Single-Leaf Merkle Forgery
Loss · ~$730K — 11,907,874.713 RARE drained from the staking contract (its entire RARE balance)
RareStakingV1.updateMerkleRoot() is meant to be callable only by the owner or one whitelisted address. Its guard is written with the comparison inverted:
SWAPP Staking Exploit — Unchecked `transferFrom` Return Value Lets a Free `deposit` Mint Staking Balance, Then `emergencyWithdraw` Drains the Vault
Loss · ~$32,196.28 — 1,286,577.59 cUSDC (raw 128,657,759,164,064, 8 decimals) drained from the S…
Staking.deposit() accepts an arbitrary tokenAddress. For any token that is not one of the three hard-coded stablecoins (USDC/USDT/DAI), it takes the "else" branch and ca…
Unverified-proxy USDT drain via recipient-only signature — signed 5-min/recipient message did not bind victim, token, amount, or nonce
Loss · 502.42 USDT (502.420508729654666584, trace balance) — the on-chain attack tx drained the…
A BNB-chain protocol exposed a delegatecall-based proxy (0xE641…106c) backed by an unverified implementation (0x8Fd3…7f0A). One of its functions (selector 0x97e76253) ta…
Unverified670471 — Balancer flash-loan callback forwarded to a victim that repays the loan with its own funds
Loss · ~$1,818.33 (484.9 mETH net profit ≈ 0.4849 ETH at fork-block prices)
The victim contract 0x6704713B... is configured to act as a Balancer IBalancerFlashLoanRecipient. Balancer's flash-loan primitive works by sending the borrowed tokens to…
Unverified6883 Fake-Pair Callback Hijack — UniswapV2 flash-swap callback trusts a freshly-created attacker pair and pays WETH into it
Loss · ~$1,006.89 (0.267592 WETH)
The victim (0x6883…) is an unverified swap helper/router that implements the UniswapV2 flash-swap callback uniswapV2Call. When invoked, it decodes an attacker-supplied p…
UPENG burn+sync drain — permissionless `burn(address,uint256)` lets anyone torch a Uniswap-V2 pair's token side, then `sync()` commits the manipulated balance as reserves
Loss · ~1.5 WBNB (1,500,999,999,999,999,999 wei) — the pair's near-total WBNB reserve [output.tx…
UPENG is a low-liquidity BEP-20 token paired against WBNB on PancakeSwap. Its UPENG/WBNB pair held roughly 21,000,000 UPENG against 1.5 WBNB at the time of the attack [o…
VDS Exploit — `deposit()` Mints 5× VDS for AVD, Redemption Refunds AVD 1:1
Loss · ~$11,136 (≈ 11,136.14 BSC-USD) profit to the attacker, drained from the AVD/BSC-USD Panca…
VDS is a token whose deposit(token, amount) lets a user deposit AVD and receive freshly-minted VDS. From the live trace, the mint rate is 5 VDS per 1 AVD (depositing 69,…
VII Finance — fees stolen from partially unwrapped `UniswapV4Wrapper` positions
Untagged1. Partial unwrap of a V4-wrapped position accumulates fees into tokensOwed and pays a proportional share to the unwrapper. 2. tokensOwed is never decremented, so the sa…
VII Finance — liquidations can be made to revert by an attacker
Untagged1. A borrower can enableTokenIdAsCollateral for a tokenId they do not hold. 2. Liquidation seizes value via transfer, which walks all enabled tokenIds. 3. normalizedToFu…
VII Finance — more value extracted by liquidations than expected (`normalizedToFull`)
1. Liquidation / value transfer walks every enabled tokenId and converts a unit-of-account amount into an ERC-6909 amount via normalizedToFull. 2. normalizedToFull multi…
weETH LRT Minter Exploit — Unprotected `0x03b79c24(address)` Token Sweep
Loss · ~$285.7K — 106.93 weETH swept, sold for 114.53 WETH (≈ $285.6K @ ~$2,494/ETH)
The vulnerable contract is a liquid-restaking-token (LRT) minter for weETH (its dispatch table exposes depositWeEth(uint256,address,address,bool), mintNrETH(), userLstBa…
WETC Token Exploit — Fee-on-Transfer + `skim`/`sync` Reserve Drain
Loss · ~$101k — attacker walked off with 101,421.95 USDT (net +101,395.4 USDT) drained from the…
WETC is a tax token. Its _transfer override taxes any transfer out of the pair as a "buy" (transferBuy, contracts_WETC.sol:104-117) and any transfer into the pair as a "…
WhereIsMyDragonTreasure — fixed redemption reward larger than the recipe cost to mint a legendary card
Loss · $47,461.35 (≈ 12.776 ETH, the full singleReward)
WhereIsMyDragonTreasure is a "treasure chest" side contract of the WhereIsMyDragon NFT-card game. Players who manage to obtain the game's legendary card can send it to t…
"b5cb0555" Exploit — Permissionless `printMoney()` Forwarder Drains a Trusted Treasury (Confused Deputy)
Loss · ~$35.3K drained from the treasury (22.49 WBNB + 1.51 ETH + 5,713.6 USDT + 4,253.6 TUSD +…
The protocol is split into two contracts that share the b5cb0555 vanity-address family:
AaveBoost Exploit — Permissionless `proxyDeposit()` Subsidy Drain
Loss · ~$14.8K — ≈48.6 AAVE drained from the AaveBoost subsidy reserve
AaveBoost.proxyDeposit(asset, recipient, amount) is meant to be a "deposit booster": when a user deposits into the AavePool through it, the booster contract adds a fixed…
Bankroll Network Stack Plus — public `buyFor(address,...)` spends any victim's LINK allowance and lets the caller skim the dividend pool it just inflated
Loss · ~12,234.48 USD (933.93 LINK net to the attacker) [output.txt:1565,1977]
BankrollNetworkStackPlus is an old-school "dividend drip" farming contract (a POWH/Bankroll-network descendant) priced 1:1 in LINK. Every buy pays a 10% entry fee, a 10%…
BankrollNetwork Stack Exploit — Stale `lastPayout` Instant-Drip Dividend Inflation
Loss · 24.586 WBNB net attacker profit (≈ 29.786 WBNB of honest user deposits drained from the c…
BankrollNetworkStack is a "drip pool" rewards contract (a fork of the well-known X-Perpetual / Bankroll family). Donations go into dividendBalance_, and a time-based dri…
BankrollStack (BankrollNetworkStack) Exploit — Flash-Loan Dividend-Drip Capture
Loss · 5,385.806 BUSD (~$5.4K) profit to the attacker, drained from the contract's dividend pool
BankrollNetworkStack is a "perpetual rewards" / POWH-style contract: users buy() shares with BUSD, pay an 8–10% fee that accumulates into a dividendBalance_ pool, and th…
BasePricePool `withdrawGOUT` price-decoupling — manipulable-balance oracle lets flash-bought QCD be redeemed for GOUT at an inflated internal rate
Loss · ~802.57 USD (≈800.97 USDT net profit in the reproduced trace)
BasePricePool is a simple "coin-to-GOUT" exchange: a user calls withdrawGOUT(amount) with a QCD (coin) allowance, the contract pulls the QCD, computes how many GOUT toke…
Batch nonce overflow freezes withdrawals — AuditVault synthetic reduction
This bug report discusses an issue that was found in the Notional Finance protocol by a group of individuals. The issue involves a function called DineroWithdrawRequestM…
BitCrown Distributor Drained via Unprotected batchTransfer — anyone could move the distributor's token balance to any recipient
Loss · ≈ 7,939.27 USDT (≈ $7,939) — 100,000 BITCROWN drained from the distributor and dumped
BitCrown is a BEP-20 token on BNB Chain that, like many low-cap launches, keeps a large portion of its supply inside a dedicated "distributor" contract (0x93b6…A2A7e) in…
BSC MEV Vault `0xb5cb…` — Authorized Helper Arbitrary Call Drains Venus vTokens
Loss · ~$1.1M first tx; campaign ~$2M across follow-ups (TenArmor)
A Venus-integrated MEV / strategy vault (0xb5cb…e1b0) gates sensitive operations (including vToken transfers via selector 0x0243f5a2) behind isAuthorized. Days before th…
FixedTokenBSwap RTV drain — attacker-supplied `path` + fake-token `transferFrom` bypass the on-chain price check, extracting a fixed 10 RTV per call
Loss · 500 RTV drained from the swap contract (~2,203.63 USD headline; ~1,617 USD in realized ET…
FixedTokenBSwap is a "swap X for a fixed 10 RTV" sale contract. The price of the input token is computed on-chain with router.getAmountsIn(tokenBOut, path), where the en…
Gangster Finance "OG Vault" Exploit — Stale `lastPayout` Drip-Pool Drain via Self-`donate()` + `harvest()`
Loss · ~0.1558 BTCB ≈ $16.5k drained from the vault's BTCB reserves
Gangster Finance's TokenVault is a yield "vault" where users stake a base token (here BTCB) and earn dividends from a drip pool (dripPoolBalance). The drip pool is paid…
Gradient Market Maker Pool Exploit — Mixed-Unit LP Share Accounting (ETH wei summed 1:1 with ERC-20 token units)
Loss · ~$5,000 — 3.0109 ETH of honest LP liquidity drained from the GRAY pool (PoC nets 2.346 WE…
GradientMarketMakerPool is a per-token "market maker" pool where users deposit ETH + a token and receive LP shares. The pool computes everything — LP shares, total liqui…
H-2: Attacker drains Morpho suppliers by inflating collateral price
Untagged500k USDC drained from Morpho suppliers via post-withdraw yield donation
H-4: Direct Morpho borrow misprices withdrawal-request collateral
UntaggedOver-borrow vs request-backed LTV (bad debt) when Morpho price ignores withdraw request
H-7: claimAccountRewards pays MORPHO the users rewards
Untagged100 reward tokens stolen to MORPHO address via permissionless claimAccountRewards
HoldSafe price-manipulation referral drain — oracle pricing of stake value and rewards from a manipulable DEX spot route
Loss · ~4,824.96 USD (6.9668 WBNB net profit, output.txt:1565)
Hold_Safe is a BSC staking/"donation" contract: a user calls Stake(usdtAmount, referrer) to "donate" a USDT-denominated amount (capped at maximumDeposit = 2000 USDT). Th…
InitcodeFactory `collectFees` — caller-authorizes via fake token `creator()` and drains ETH on a non-WETH `token1`
Loss · ~2,383.25 USD (≈ 0.9793 ETH stolen)
Factory (0x930f9f…) is a launchpad that mints its own ERC-20 tokens and seeds a Uniswap V3 pool (token↔WETH, 1% tier). It retains the V3 liquidity NFT itself and exposes…
KittenSwap — `RebaseReward` fails because of incorrect token handling
Untagged1. notifyRewardAmount only accepts Kitten, but incentivize accepts any token. 2. On claim, every reward token's share is deposited as Kitten via deposit_for. 3. Equal-we…
KittenSwap — Lack of `lastMintedPeriod` update allows unlimited minting of Kitten
Untagged1. Minter.updatePeriod() is meant to mint weekly Kitten once per epoch period. 2. The guard is if (currentPeriod > lastMintedPeriod). 3. After minting, the code never wr…
Meta Pool (mpETH) Exploit — Free `mint()` on a Native-ETH ERC4626 Vault
Loss · PoC measured profit: 8.892 ETH in cash + 77.79 mpETH (≈ 85.8 ETH @ 1.1029 ETH/mpETH) ≈ ~9…
Staking is Meta Pool's liquid-staking vault. mpETH is its ERC4626 share token, but the asset is native ETH, not the ERC20 _asset (WETH) that OpenZeppelin's ERC4626Upgrad…
MOMO Buyback-Bot Exploit — Permissionless, Slippage-Free `5ff02eae()` Sandwiched on a Thin USD1/MOMO Pool
Loss · ~$48.3K — 48,264.80 USD1 extracted from the MOMO buyback bot
0x8490… is a buyback/treasury bot for the MOMO token. It holds a pile of USD1 (48,758.887 USD1 at the fork block) and exposes a public function — selector 5ff02eae() — t…
Notional Exponent H-10: caller-controlled TradeType (EXACT_IN → EXACT_OUT) drains the vault on redemption
UntaggedNotional Exponent H-11: expired-PT redemption uses `sy.redeem(..., minTokenOut: 0)` → sandwich drains the user
UntaggedNotional Exponent H-3: Dinero withdraw manager over-withdraws via batch-ID overlap
UntaggedNotional Exponent H-6: `uint16 s_batchNonce` overflow permanently bricks Dinero withdrawals
UntaggedNotional Exponent H-8: PendlePTOracle assumes 1 SY == 1 Yield Token → inflated PT price → bad debt
UntaggedNotional Exponent H-9: hardcoded `use_eth = true` on Curve V2 exit locks WETH-vault funds
UntaggedPanoptic Hypovault — poolExposure1 premium operands reversed
1. Short premium is an asset; long premium is a liability. 2. poolExposure0 correctly does short − long; poolExposure1 reverses operands. 3. NAV understated (1050 vs 125…
ParaSwap Augustus — arbitrary `exchangeData` lets an unprivileged caller drain any account that approved the router — $2,299 DAI
Loss · 2,298.68 USD (2,299.037 DAI) — full drain of the victim account's DAI balance [output.txt…
ParaSwap's AugustusSwapper is a DEX-aggregation router. Its simpleSwap(SimpleData) entry point is designed to take a fromToken/fromAmount from the caller and execute an…
PegaBall — `buyGamesFrom` self-funds ticket purchases from the contract balance instead of `msg.value` — free vendor/referrer cut drain
Loss · ~0.579 ETH (~1,512.85 USD) — 129 free ticket purchases draining vendor + referrer cuts [o…
PegaBall is an on-chain PowerBall-style lottery. Tickets are bought through buyGames / buyGamesFrom, both payable. The intended model is: a buyer sends amount * gamePric…
Resupply Finance Exploit — Empty-Vault Share-Price Inflation → `exchangeRate = 0` → Uncollateralized Borrow
Loss · ~$9.6M — attacker netted 9,806,396.36 USDC from a 4,000 USDC flash-loan, zero starting ca…
Resupply lets users borrow its reUSD stablecoin against ERC-4626 vault shares (here, a CurveLend crvUSD/wstUSR lending vault). The collateral is priced by a one-line ora…
Silo Finance Exploit — Untrusted Swap/Silo Targets in `openLeveragePosition` Let Attacker Re-route a "Swap" into `Silo.borrow`
1. Silo Finance ships a public openLeveragePosition helper (the "Silo leverage helper", 0xCbEe4617…829DF9) that takes three user-supplied argument blobs: a FlashArgs (fl…
SinstakeNetworkZombie dividend-donation flash-drain — flash-borrowed ZOMBIE donates dividends that the same-tx buyer/seller immediately withdraws, netting excess ZOMBIE convertible to WBNB
Loss · ~705.13 USD (~1.1016 WBNB realized as profit) [output.txt:1564,1565,1784]
SinstakeNetworkZombie is a "dividend yield" contract: users deposit ZOMBIE (the project ERC-20), receive internal dividend-bearing shares (tokenBalanceLedger_), and earn…
Stead Farm Exploit — Permissionless STEAD Drain via Un-Access-Controlled Function
Loss · ~$14.5k — 135,000 STEAD (6 decimals) drained from the Farm contract
The Stead protocol deployed a farming / staking contract (proxy 0xf9FF…, implementation 0xca9d57…) that was funded with STEAD tokens to pay out yield. Its decompiled dis…
Superfluid Locker — Pumponomics can be skipped via `provideLiquidity`
Untagged1. Owner pre-sends WETH into the locker (not via provideLiquidity). 2. Calls provideLiquidity{value: dust}(supAmount). 3. Only dust * 1% is pumped (buy SUP); the positio…
Superfluid Locker — Staked tokens inside FluidLocker can be withdrawn without Unstake
Untagged1. Owner stakes all FLUID in the locker (_stakedBalance = balance). 2. provideLiquidity(supAmount) does not check available balance — staked tokens leave to Uniswap. 3.…
TokenFactory fake-router LP drain — caller-supplied swap infrastructure is trusted without verifying the returned pair belongs to the new token
Loss · ~657.17 USD (~1.006 WBNB of pair reserves, plus the attacker also received ~9.94e26 HODOG…
TokenFactory is a BNB Chain "token-launchpad" contract: anyone pays a small fee, calls createTokenAndAddLiquidity, and the factory deploys a new ERC20, approves a Uniswa…
TokenVault (Gangster Finance) — same-tx donate+deposit inflates fresh shares against the drip pool
Loss · ~3,226.51 USD (4.9836 WBNB) — attacker before 1.4702 WBNB, after 6.4538 WBNB
TokenVault is a staking/"vault" contract from Gangster Finance (an early BSC dividend-yield project). Holders stake a BEP20 token and earn a share of a "drip pool" that…
TSAggregatorGeneric arbitrary swap-target calldata drains victim allowance — attacker-chosen `swapRouter`/`data` lets `swapIn()` call any function on any token the aggregator is allowed to spend
Loss · 1,300.00 USDT (BEP-20) — 1,300 10*18 [output.txt:1621]
TSAggregatorGeneric is the THORChain Saver-style EVM swap aggregator: a user deposits an input token, the aggregator swaps it through some DEX and forwards native BNB to…
WAL-E Coin proxy reinitialization → authorized buyback drain — public `initialize()` with no guard rewrites owner/router and unlocks `triggerZeusBuyback`
Loss · 1.415367204023272901 BNB (~$430 at the time)
WAL-E Coin ($WAL-E) is a BSC "dividend + buyback" token deployed behind an ERC-1967-style transparent upgradeable proxy. The implementation, RewardsChain, performs all o…
Aria — stRWIP is always minted for RWIP in a 1:1 ratio
1. burnTicket always mints stRWIP equal to the ticket's RWIP amount (1:1). 2. unstake redeems stRWIP at the live exchange rate balance / supply. 3. After rewards inflate…
Beta (BETA) Presale — public `set()` + per-sender-only deposit cap let a recycled flash loan drain the presale
Loss · 1.921686798824852706 WBNB + 46.474821659738262175 BUSD (≈ 1,700+ USD at the time)
The Beta token presale contract PresaleBEP20 has two compounding flaws in its deposit() flow. First, anyone can call the public, unguarded set() to overwrite withdrawAdd…
BitallxSC payout-array bypass drains victim USDT balance — public `BitallxPayOut` validates only `totalSendAmount`, never `sum(amount[])`
Loss · 2,029.47 USDT (2,029,473,999,999,999,986,000 wei) — full victim contract balance [output.…
BitallxSC is a small BSC rewards/payout contract holding ~2,029.47 USDT in treasury. It exposes a function BitallxPayOut(tokencontract, wallet[], amount[], totalSendAmou…
Blackhole — inverted `setRouter` zero-address check bricks pool launches
1. setRouter(address _router) is meant to let the owner update the DEX router used when a GenesisPool launches and adds liquidity. 2. The require is inverted: require(_r…
Blackhole — Reward token in `GaugeFactoryCL` can be drained by anyone
Untagged1. createGauge is external with no authorization. 2. Each call seeds Algebra eternal farming with a hardcoded 1e10 of _rewardToken pulled from the factory. 3. Anyone can…
Blueberry HyperliquidEscrow — tvl() omits in-flight USDC
1. Non-USDC assets add same-block in-flight bridge amounts into TVL. 2. The USDC branch only counts balanceOf and skips in-flight. 3. Deposit against understated TVL min…
C-02: Missing packet ID in finalizeOpen causes NFT loss
UntaggedPacket NFT stuck in contract; INSTANT_OPEN reverts; user loses NFT with no cards
CAP Labs — decimal count creates an inaccurate staked price
The adapter multiplies by capTokenDecimals and divides by stakedTokenDecimals instead of applying 10decimals. Six- and eighteen-decimal assets therefore receive a nonsen…
CAP Labs — fee auction charges for zero assets
FeeAuction.buy does not bind a purchase to an auction or require a non-empty basket. A front-runner drains the basket, then the victim pays the doubled price for zero ou…
CAP Labs — health and slashable collateral disagree
coverage includes current collateral while slashTimestamp limits slashing to the previous epoch. A fresh rescue deposit improves health but cannot be slashed in liquidat…
CAP Labs — inconsistent vault balance tracking bricks borrowing
An untracked donation supplies physical tokens for burn, but the burn still decrements totalSupplies. The accounting invariant falls below totalBorrows and subsequent bo…
CAP Labs — unvalidated vault address inflates interest rates
VaultAdapter.rate accepts any vault address and trusts its currentUtilizationIndex/utilization responses. A malicious implementation returns extreme values and permanent…
CAP Labs PriceOracle — global staleness period rejects valid feeds
CAP's oracle stores one staleness period for all assets. Configuring one hour for hourly ETH feeds makes a valid daily USDC-like report revert after five thousand second…
Chat points manipulation via custom Uniswap V4 pools
UntaggedFull chat points for ~1% capital via unvalidated custom pool key
Cork Protocol Exploit — Permissionless Market Creation with Attacker-Controlled `exchangeRateProvider`
Loss · ~$12M — 3,760.88 wstETH drained from the live wstETH↔weETH PSM/Vault market
Cork Protocol lets a "Module" (a PSM + Liquidity-Vault pair) be created for a Redemption-Asset / Pegged-Asset (RA/PA) couple. Each module mints two receipt tokens per ep…
Crosswise MasterChef trusted-forwarder hijack — public setter with no access control enables arbitrary `_msgSender()` spoofing
Loss · ~4.16 WBNB (the public PoC drains this from the CRSS/WBNB pair; the on-chain attack drain…
Crosswise's MasterChef inherits OpenGSN's BaseRelayRecipient, which overrides _msgSender() so that when the caller is the trustedForwarder, the real sender is read from…
DODO Cross-Chain DEX — `withdrawToNativeChain` swaps arbitrary ZRC20 inventory
1. withdrawToNativeChain decodes DODO MixSwapParams from the user message. 2. _doMixSwap approves params.fromToken for the deposited amount — no check that fromToken ==…
DODO Cross-Chain DEX — empty `swapData` skips swap and pays high-value target 1:1
1. _doMixSwap short-circuits when swapData is empty: return amount. 2. No check that the deposit token equals decoded.targetZRC20. 3. Attacker deposits 100 AVAX.ZRC20, e…
DODO Cross-Chain DEX — missing `msg.value` check on ETH placeholder drains ZRC20
1. For non-ETH inputs, the gateway pulls tokens via transferFrom. 2. For zrc20 == _ETH_ADDRESS_, that pull is skipped — but msg.value is never checked. 3. Attacker claim…
DODO Cross-Chain DEX — swap output token ≠ withdrawal target drains gateway
1. onCall performs _doMixSwap(..., params.toToken) then withdraws decoded.targetZRC20. 2. Nothing requires toToken == targetZRC20. 3. Attacker crafts a message: swap BTC…
DODO Cross-Chain DEX — unauthorized claim of non-EVM chain refunds
1. Refunds store a walletAddress blob (20 bytes for EVM, longer for BTC/etc.). 2. claimRefund only decodes receiver when length is exactly 20; otherwise receiver stays m…
DogeAlliance sync() reserve manipulation — LP pairs with token balances desynced from reserves drained by permissionless sync + swap
Loss · ~990.33 USD (1.5044 WBNB at the time of the incident) — attacker net profit per [output.t…
DogeAlliance (DOGEALLY, BSC) is a meme token that listed across several PancakeSwap/ApeSwap-style DOGEALLY/WBNB, DOGEALLY/BUSD and DOGEALLY/CAKE LP pairs. The DOGEALLY t…
Dumbo DUM staking reward inflation — permissionless, repeatable `distribute()` lets an attacker mint compounding rewards inside one transaction
Loss · 628.447753459629926384 BUSD (≈ 628.45 BUSD) — reproduced locally [output.txt:1564-1565]
Dumbo ran an OlympusDAO-style "rebasing" staking system: users stake DUM, receive the receipt token sDUM, and a Distributor contract periodically calls distribute() to m…
IRYSAI Exploit — Backdoored `transferFrom` Lets the Tax Wallet Drain the LP Pool
Loss · ~$69.6K — 107.46 WBNB drained from the IRYSAI/WBNB PancakeSwap pair
IRYSAI's transferFrom contains a hidden privilege for the tax wallet: when msg.sender == _taxWallet, the function performs the balance move but skips the allowance deduc…
KRC Token Exploit — Fee-on-Transfer Token Burns From Its Own Pool, Desyncing Reserves
Loss · ~$7,155 — 7,154.81 USDT drained from the KRC/USDT PancakeSwap-V2 pair
KB (the KRC token) is a fee-on-transfer / reflection token. When tokens are transferred into the AMM pair, its _transfer override does something fatal: it burns a slice…
LayerEdge — Incorrect tier tracking when tier 3 staker exits
Untagged1. With 15 stakers, tiers are correctly (3, 4, 8). 2. A Tier-3 staker fully unstakes → expected (2, 4, 8). 3. Because new_t2 == old_t2, the removal path only rewrites ra…
LayerEdge — When stakerCountInTree increases, some users receive less interest
Untagged1. Staking grows from 14 → 15 users: tiers should go (2,4,8) → (3,4,8). 2. Rank 7 must promote T3 → T2. 3. Because new_t2 == old_t2, the add path only updates old_t1 + o…
LEND H-11: cross-chain borrow ignores per-chain token decimals (~1e12× overborrow)
UntaggedLEND H-18: incorrect `srcEid` check in `borrowWithInterest` (cross-chain debt reads 0 → liquidation evasion)
UntaggedLEND H-20: multiple cross-chain borrows reuse the same collateral (Nx overborrow)
UntaggedLEND H-3: both cross-chain mappings populated bricks `borrowWithInterest` (liquidation evasion)
UntaggedMBU Token Exploit — Decimal-Scaling Bug in `deposit()` Mints ~1e18× Too Many Tokens
Loss · ~2,157,126 BUSD (~$2.16M) drained from the MBU/USDT PancakeSwap pair
The deposit() entry point on 0x95e9… accepts a token (here WBNB), prices it in USDT via a spot AMM oracle, then mints MBU to the depositor based on that USD value divide…
Nalakuvara / LotteryTicketSwap50 Exploit — Fixed-Payout Redemption Drains the AMM Pool
Loss · 105,470 USDC (net profit to attacker, drained out of the NATA/USDC liquidity pool)
LotteryTicketSwap50 lets a user "buy lottery tickets" with USDC (transferToken) and later "destroy" those tickets to get a refund (DestructionOfLotteryTickets). The refu…
RICE / BentoBox-Clone Exploit — Signature-less `setMasterContractApproval` Lets Anyone Drain Any Depositor
Loss · ~34.52 WETH ($88.1K) — drained from a single depositor of a BentoBox/DegenBox-style vault
The vulnerable contract is a BentoBox/DegenBox clone (the function selectors, parameter layouts, and emitted events — LogRegisterProtocol, LogSetMasterContractApproval,…
Subsequent cross-chain borrow skips accrued interest — AuditVault synthetic reduction
This bug report discusses an issue that was found by a group of individuals on a platform called GitHub. The issue involves borrowing the same asset more than once on a…
Uniswap The Compact — incorrect emissary storage slot breaks authorization
1. Emissary config slots must be keyed by (scope, sponsor, lockTag). 2. Buggy packing writes lockTag over the memory region holding sponsor. 3. All sponsors share one co…
Unverified Base airdrop-claim contract drained via constructor-time claim spam — per-claimant eligibility keyed on `msg.sender` with no nonce/code/allow-list guard
Loss · 0.208333333333333384 ETH (≈ 551.22 USD at the time) — full victim balance drained
The victim at 0x91a1…193D is an unverified Base contract exposing a public claim() that sends the caller a fixed per-claim chunk of ETH and records that the caller has c…
Unverified BSC Victim Drain (mintTokens 0x88417d5c) — missing access control lets anyone sweep the contract's ERC20 balances
Loss · 5,658.46 USD (reported in @KeyInfo; reproduced drained balances below)
The victim contract at 0x000004…D0000 exposes a function with selector 0x88417d5c whose decoded signature is mintTokens(uint256,bool,bool,(address,uint256)[]) (the test'…
Unwarp Exploit — Permissionless `unwrapWETH(amount, recipient)` Self-Balance Drain
Loss · 3.9813269016365735 WETH (≈ $9K) — the vulnerable contract's own pre-existing WETH balance
The vulnerable contract exposes a permissionless function unwrapWETH(uint256 amount, address recipient). It unwraps the contract's own WETH (WETH.balanceOf(this)) into n…
Usual Money Exploit — `VaultRouter.deposit` Routes Through an Attacker-Controlled Swap Venue With No Real Slippage Floor
Loss · ~$43,000 — 15.925 WETH extracted out of Usual's VaultRouter / WrappedDollarVault deposit…
VaultRouter.deposit(augustus, USD0++, amountIn, minTokensToReceive, …, swapData) lets a depositor hand in USD0++, which the router unwraps 1:1 into USD0 and then swaps i…
YDT Token Exploit — Permissionless `proxyTransfer()` Drains the Liquidity Pool
Loss · ~41,337 USDT drained from the YDT/USDT PancakeSwap pair (PoC reports a final balance of 4…
YDTMainContract is a fee-on-transfer ("tax") token whose sub-modules (tax, referral, deflation, liquidity, LP-tracking) are allowed to move tokens around without re-trig…
Yearn yBOLD — Deposit after loss report free-rides collateral recovery
Untagged1. Victim deposits into the strategy. 2. Stability Pool liquidation burns BOLD; collateral gains are unrealized. 3. Keeper report() books a loss (PPS drops) because harv…
Yearn yBOLD — Steal 25% of first depositor funds via share inflation
Untagged1. Fresh strategy has totalSupply = 0 and no burned dead shares. 2. Attacker deposits 1 wei → 1 share, then donates until totalAssets = 1 + victimDeposit/2. 3. Victim de…
Aera Contracts v3 — incorrect received-swap-amount calculation lets guardians bypass the daily loss limit
1. Aera's slippage hook enforces a daily loss limit on guardian-directed swaps. To do so, its after-hook measures how much tokenOut the vault received as a balance delta…
AIRWA Exploit — Permissionless `setBurnRate()` + Zero-Value Transfer Pool-Reserve Annihilation
Loss · ~56.73 BNB (≈ $34,205 of BSC-USD liquidity drained from the AIRWA/BSC-USD PancakeSwap pai…
AIRWA is a fee/burn token whose burn rate is settable by anyone through a public, unauthenticated setBurnRate(uint256) function (selector 0x189d165e, no onlyOwner). When…
AmpKashi (Kashi AMP/USDC) flash-loan oracle manipulation — borrow against a stale spot price
Loss · 572.31 USDC (attacker net profit; the AMP collateral left in the pair was effectively wor…
Kashi is SushiSwap's BentoBox-based money market: each lending market is a thin KashiPairMediumRiskV1 clone that takes one collateral token and lends one asset token, wi…
Aventa / IntelliQuant reward-claim drain — claim size is computed from a spot, attacker-controllable token balance
Loss · ~16,019,528 AVENTA (≈ 16.0 M tokens), monetised to ~3.9 ETH by the PoC batch of 12 helper…
AventaRewardClaim.claim(user) is meant to pay AVENTA rewards to existing IntelliQuant holders. The amount it pays is IntelliQuant.balanceOf(user) read at call time — not…
BITDOG token — public `changeRouterVersion` hijacks swap router & drains contract BNB
Loss · 2.101368297037048768 BNB (~2.10 BNB)
BITDOG is a fee-on-transfer BEP-20 that holds its collected swap fees in BNB inside the token contract itself. When any transfer pushes the contract's own token balance…
Blueberry HyperVaultRouter — missing asset index check mints shares for any token
1. deposit(asset, amount) looks up assetIndexes[asset] and requires _isAssetSupported. 2. Unregistered tokens return mapping default 0, and USDC is hardcoded as index 0.…
Blueberry TVL share inflation — AuditVault 61480
TVL excludes in-flight assets, so a deposit mints twice the fair share amount.
BTNFT Exploit — Permissionless Reward Theft via a Broken `_update` Override
Loss · 19,025.92 BUSD received by the attacker (19,158.41 BTT reward drained, then dumped)
BTNFT is an ERC-721 (OpenZeppelin v5) where each NFT carries a 1-year linear vesting schedule of BTT tokens. To let an owner "redeem" an NFT's vested rewards, the contra…
Burve — Incorrect handling of ERC4626 vaults with fees
Untagged1. Pool deposits user tokens into an ERC4626 that takes a 1% deposit fee. 2. Protocol still credits full value despite fewer shares minted. 3. User withdraws full credit…
Burve — Incorrect tax distribution when adding value single-sided
Untagged1. Single-sided adds charge a tax meant for existing LPs. 2. valueStaked is incremented before tax is written into earningsPerValueX128. 3. New LP is already in the deno…
Burve — Reserve share overflows due to strict reward calculation
Untagged1. ReserveLib.deposit mints shares as amount * shares / balance. 2. Dust residuals leave balance tiny while amount > 0 still mints. 3. Repeated inflation drives shares n…
Burve H-6: fee bypass in `ValueFacet.removeValueSingle` (variable used before assignment)
UntaggedBurve: an attacker captures unclaimed fees by timing a deposit around range re-entry
UntaggedFlyLong (FLG) — public balance-forger lets any caller fake the LP's token balance and drain the WBNB side of the pair — access-control/missing-auth
Loss · ~1.73 BNB (PoC extracts 1.7258625 BNB; ~1 BNB of dust remains in the pair as 0.0001726035…
FlyLong is an obfuscated BSC ERC-20 whose code keeps a custom liquiditySwapFrom mapping as its "real" balance ledger (balanceOf just reads it). Two of its functions are…
Forte Float128 — [H-01] Early 72-digit adjustment in sqrt wrong exponent
Untagged1. Large-path sqrt computes a 73-digit rMan via Uint512.sqrt512. 2. The code trims to 72 digits (rMan /= 10; ++rExp) before rExp /= 2. 3. Integer division drops the +1 (…
Forte Float128 — [H-02] Sqrt silently stops the entire call frame on packed 0
Untagged1. Mathematically, sqrt(0) = 0. 2. Float128 uses assembly stop() on packed zero — equivalent to return(0,0) for the entire call frame. 3. Because sqrt is internal pure,…
Forte Float128 — [H-04] eq ignores L_MANTISSA_FLAG / dual encodings
Untagged1. Mantissas may be M (38 digits) or L (72 digits); the L flag is bit 241 of the packed word. 2. eq only checks unwrap(a) == unwrap(b). 3. 1.0 encoded as L (1e71 10^-71)…
Forte Float128 — [H-05] Precision loss in toPackedFloat for mid-range mantissas
Untagged1. Mantissas with 39–71 digits sit between M-max (38) and L-min (72). 2. toPackedFloat decides M vs L from the exponent alone. 3. For 2^235 with exponent -51, the encode…
Impermax V3 Exploit — Self-Liquidation Debt Wipe via `restructureBadDebt`
Loss · ~$300k total (per QuillAudits / SlowMist). This single reproduced run nets 34.60 WETH ≈ $…
Impermax V3 lets you deposit ERC-20s into a Borrowable pool (you get pool shares whose value is (cash + outstandingDebt) / totalSupply) and borrow against a tokenized Un…
Kinetiq — `receive()` re-stakes Core-returned HYPE and bricks confirmWithdrawal
1. On HyperEVM, HYPE is the native gas token. Undelegations from Hypercore arrive as native ETH-like transfers to StakingManager. 2. receive() external payable { stake()…
Laundromat Exploit — Free Ring-Membership Drains a Dormant Mixer
Loss · ~$1.5K — 1.0 ETH (the entire pool, deposited by one honest participant)
Laundromat is an ancient on-chain mixer that implements a linkable ring signature (the academic "Möbius"/ring-signature ETH-mixing scheme). It is parameterised by a fixe…
Level zero heartbeat blocks claims — AuditVault 63737
A zero heartbeat is treated as an invalid oracle state and causes every reward claim to revert.
Life Protocol Exploit — Asymmetric Bonding Curve: Pump the Buy Price, Dump at 90% of the Peak
Loss · ~18,045 BUSD drained in the reproduced transaction (the original incident is reported at…
LifeProtocolContract is a "bonding-curve"-style market maker for the LIFE token, priced in BUSD. It keeps a single mutable currentPrice (:1071).
MultiTransferSwap ETH refund drain — loop-accumulation bug lets attacker reclaim msg.value against the contract's own balance
Loss · ~0.339 ETH (339,014,011,988,554,657 wei) drained from the contract; attacker net ~0.3366…
MultiTransferSwap is a thin Uniswap-V2 wrapper that lets a caller swap ETH for an exact amount of some output token, repeated times times in a single call. The author me…
R0AR (1R0R) Staking Exploit — Backdoored `user.amount` + Self-Capping `EmergencyWithdraw()` Drain
Loss · ~$777K — 100,000,000.0999 1R0R + 26.777 R0AR/WETH LP tokens drained from the staking cont…
R0ARStaking is a single-pool staking contract: users stake R0AR/WETH LP tokens and accrue 1R0R rewards. It exposes three withdrawal-ish paths: withdraw(), harvest(), and…
tCDP `transferFrom` allowance-swap bug drains holders' tokens — ERC-20 `transferFrom` debits the wrong allowance slot
Loss · ~2.02 ETH (the attacker's net profit after the 0.1 ETH seed); see output.txt:1565
tCDP is an ERC-20 wrapper token for a leveraged ETH/DAI "CDP" position held on Compound — holding tCDP entitles the owner to a proportional slice of the contract's cETH…
Unverified `0x607742A2` Exploit — Permissionless `uniswapV3SwapCallback` Approval Drain
Loss · ~$62.3K — 22.51 WETH + 27,260 USDC drained from a single approving wallet
The contract at 0x607742A2 is a generic "router/swap-executor" helper that interacts with Uniswap-V3-style pools. It implements uniswapV3SwapCallback(int256 amount0Delta…
Virtuals — new validator receives historic voting credit and the full reward
A validator score should count actual engagement. When a validator is initialized, the audited code assigns its base score to the total number of past proposals. That ma…
Virtuals — public impact recalculation redirects reward allocation
Impact values determine the allocation used to mint rewards. updateImpact is public, and it persists a recalculated allocation using the current datasetImpactWeight. Aft…
Virtuals — stale `promptMulti` cache burns and misroutes user payments
promptMulti tries to cache an agent token-bound account for consecutive identical agent IDs. It loads an address when the ID changes, but never assigns the new ID to pre…
Virtuals Protocol — anybody can control a user's delegate via `AgentVeToken.stake()` with 1 wei
1. AgentVeToken.stake(amount, receiver, delegatee) mints amount veToken to receiver, then unconditionally calls _delegate(receiver, delegatee). 2. Only the caller's own…
YB Token Exploit — Sell-Triggered Uncompensated Pool-Reserve Burn (`sync()` price manipulation)
Loss · 15,261.68 BUSD (~$15.3K) drained from the YB/BUSD PancakeSwap pair
The YB token's transfer-fee machinery burns YB directly out of its own AMM pair's balance and then calls pair.sync() on every taxed sell. The relevant call lives in swap…
YieldFi CCIP: every inbound message reverts when decoded (`uint32` vs `uint64` chain selector)
UntaggedYieldFi CCIP: missing source validation lets an untrusted chain drive privileged mint/unlock
UntaggedYieldFi YToken: wrong `owner` (`msg.sender`) passed to `Manager.redeem` in delegated withdrawals
Untagged0x MainnetSettler Exploit — Arbitrary `transferFrom` via the BASIC Action's `sellToken == address(0)` Confused-Deputy Fall-Through
Loss · 3,008 USDT (3,008,000,000 raw, 6 decimals) — lifted from the victim's USDT balance via US…
1. The 0x MainnetSettler.execute(AllowedSlippage, bytes[] actions, bytes32 zidAndAffiliate) entry point is takerSubmitted — i.e. the caller (msg.sender via the transient…
1inch Fusion V1 `Settlement` Exploit — Yul Calldata-Length Underflow Hijacks the Resolver Dynamic Suffix
Loss · ~$4.5M across affected resolvers (this PoC reproduces 1,000,000 USDC drained from a singl…
1inch Fusion's Settlement contract fills Fusion orders by calling the Aggregation Router V5's fillOrderTo, and appends a "dynamic suffix" (totalFee, resolver, token, rat…
540 seconds is used instead of 540 days — AuditVault synthetic reduction
The report discusses a bug found in the Superfluid locking contract, where the function _getUnlockingPercentage() incorrectly uses the number 540 instead of 540 days, le…
Alkimiya SilicaPools Exploit — `uint128(shares)` Truncation Inflates Redemption Payout
Loss · ~$95.5K — 1.14015390 WBTC drained from the SilicaPools contract
SilicaPools issues paired ERC-1155 long and short tokens against collateral. The amount of collateral and the per-pool sharesMinted accumulator are tracked in uint128 st…
BBX Token Exploit — Stuck Daily-Burn Repeatedly Drains the Pool's BBX Reserve
Loss · ~11,673.92 BUSD (≈ $11,902) drained from the BSC-USD/BBX PancakeSwap pair
BBXToken's _transfer override contains a "daily deflation" feature: once a day, it burns burnRate (3%) of the liquidity pool's BBX balance directly out of the pair and t…
Biconomy Composability — [C-01] Missing DelegateCall check
1. executeComposableDelegateCall is meant only via smart-account CALLTYPE_DELEGATECALL. 2. There is no check that address(this) differs from the module’s immutable deplo…
Blueberry approved withdrawal drain — AuditVault 61458
requestRedeem debits escrow without checking that the caller is an approved withdrawal owner.
Burve — DoS on `mint()` and `burn()` due to overestimation of available liquidity
Untagged1. Every mint/burn runs compoundV3Ranges → collectAndCalcCompound. 2. With 2 equal ranges and 1 wei residual, nominal liq is computed as 14. 3. Real mintable liquidity i…
Burve — First deposit front-running attack
Untagged1. Alice mints 1 wei liquidity → 1 share (no dead shares). 2. Alice donates 1e18 of liquidity tokens, inflating totalNominalLiq. 3. Charlie mints 2e18 → shares = 2e18 *…
DCF Token Exploit — Transfer-to-Pair Reserve Burn Inflates DCF Price
Loss · ~442,028 BSC-USD (~$442K) drained from the DCF/BSC-USD and DCT/BSC-USD PancakeSwap pairs
DCF is a "deflationary" ERC20. Its overridden _transfer (contracts_DCF.sol:124-165) contains a hook that fires whenever someone transfers DCF to the liquidity pair. In t…
DIA Spectra — fee dropped during the interchain oracle callback (permanent DoS)
OracleRequestRecipient.handle() is the destination-chain entrypoint the Hyperlane relayer calls to deliver an inbound oracle request. To answer it, handle() dispatches a…
DUCKVADER Exploit — Permissionless Free-Mint via Broken `buyTokens()` + Storage Shadowing
Loss · ~5 ETH total in the live attack (200 mint-loops). The extracted PoC uses 10 loops and sti…
DUCKVADER's buyTokens(uint256 amount) is supposed to be a paid mint endpoint. It is catastrophically broken in three independent ways (Contract.sol:700-712):
ERC-20 fees are permanently locked in Treasury — frozen funds
Loss · ERC-20 fee balances sent to Treasury cannot be recovered
The Treasury exposes a native-ETH withdrawal only. ERC-20 fee tokens accumulate at the contract and the attempted token recovery selector reverts, leaving the balance fr…
H2O Token Exploit — `skim()`-Triggered Self-Minting Reward Drain
Loss · 22,470.89 USD (≈22,470 BSC-USD), drained from the H2O contract's own reserve via the H2O/…
H2O is a "reflection"-style token. On every transfer where the sender is the AMM pair, it runs a hidden reward routine _calulate() (Token.sol:509-562) that (a) mints sid…
InfiniFi — Referencing the gateway balance in `increaseUnwindingEpochs` can DoS the function
Untagged1. LockedPositionTokens are transferable until used to vote. 2. Bob transfers his position tokens to the gateway. 3. Alice deposits her own shares and approves only her…
InfiniFi — StakedToken holders can circumvent restriction by approving another address to withdraw
Untagged1. Alice holds siUSD and is action-restricted (cannot transfer/withdraw). 2. Alice approves an unrestricted third party for her shares. 3. Alice's own withdraw reverts w…
Kinetiq LST — precision truncation on stake causes accounting insolvency
1. HyperCore books HYPE with 8 decimals → transfers must be multiples of 1e10 wei. 2. _distributeStake sends truncatedAmount = amount / 1e10 * 1e10 but recordStake mints…
PTM (Phoenix To Moon) token — public `addLiquidity()` lets anyone spend the token contract's own PTM/USDT into the LP
Loss · 552.63 USDT (≈ $553) net profit to the attacker [output.txt:1564-1565]
PTM ("Phoenix To Moon") is a BSC reflection/dividend token whose fee machinery siphons part of every transfer into the token contract itself (address(this)): a 0.5% liqu…
Pump / TiPTAG Token Exploit — Permissionless Pre-Listing Liquidity Seeding Drains the Bonding-Curve Listing
Loss · ~11.29 BNB (~$6.4K) — net profit, drained across 4 Pump/TiPTAG tokens in one tx
The Pump (TiPTAG) launchpad mints tokens that live on a bonding curve until enough is sold, at which point buyToken() auto-lists the token by dumping liquidityAmount (20…
RnsPay arbitrary `dexRouter` call drains any token a victim approved to the protocol — attacker-supplied exchange target lets `pay()` execute `transferFrom` against arbitrary victims
Loss · 1,050 USDC (~$1,050), laundered to 0.4632 ETH via Uniswap V2 output.txt:1565
RnsPay is a payments contract intended to route a user's payment token through a DEX and forward the converted receipt token to a merchant. To support that, its pay() fl…
SamPrisonman (SBF) Exploit — Externally-Controlled Balance Write Lets an Attacker Zero the AMM Pool Reserve
Loss · ~$14K — 6.5793 WETH drained from the SBF/WETH Uniswap V2 pair
SamPrisonman is a "SBF / Sam Prisonman" meme token whose ERC20 _transfer does not decrement the sender's balance the normal way. Instead it makes an external call to a h…
SBR Token Exploit — `skim()` + broken token `transfer` zeroes a Uniswap-V2 reserve
Loss · ~8.495 ETH (8,495,031,867,920,840,930 wei) — the entire WETH side of the SBR/WETH pool
The SBR token has a broken transfer implementation: calling transfer(x, 0) (or otherwise transferring out a tiny/zero amount) wipes the entire balance of the caller inst…
SIR (Leverage) Exploit — Dirty Transient-Storage Slot Turns `uniswapV3SwapCallback` Into an Open Drain
Loss · ~$353.8K — 17,814.86 USDC + 1.4085 WBTC + 119.87 WETH drained from the SIR Vault singleton
SIR's Vault uses EVM transient storage (EIP-1153, tstore/tload) as scratch space during a leveraged mint:
StackMarket graduated-account flash-loan drain — buy path swaps a Uniswap V3 pool with caller-controlled (zero) slippage, then unwinds at the inflated pool price
Loss · 0.56 WETH (per @KeyInfo; single-attack tx magnitude)
StackMarket is a Base bonding-curve launchpad: every "account" gets its own ERC-20 (StackToken) that trades on an internal AMM (BondingCurve, y = A·x²/B) until 50 % of t…
SWT token burn-then-sync drain — permissionless `burn(address,uint256)` desyncs an AMM pair's reserves before `sync()`
Loss · ~0.40 WAVAX (the pair held ~0.8957 WAVAX; attacker netted ~0.3957 WAVAX after a 0.5 AVAX…
SWT is an unverified ERC-20 on Avalanche paired against WAVAX in a standard Uniswap-V2-style AMM (0x8234…c5CF). The token ships a burn(address from, uint256 amount) func…
SXT — [C-01] Accepting duplicate signatures from one signer
UntaggedThreshold = 2. Attacker submits the same valid (v,r,s) twice. Both recover to one attestor; both count. validateMessage returns true.
Unlocking percentage formula applies an 80% penalty — AuditVault synthetic reduction
The bug report discusses an issue with the FluidLocker::_getUnlockingPercentage() function in the Superfluid locking contract. The function incorrectly divides one of th…
Unverified `swapit()` helper — public function lets anyone trigger a contract-owned USDC swap through the same AMM pool, harvesting the price impact
Loss · 980.32 USDC (~$980) drained from the vulnerable swapper's own balance
The victim is a small, unverified "swap helper" contract holding a USDC balance and bound to the OFFICIALYE token (a low-cap Base memecoin, 0xedb54f9ffA78f0A0d50dC0c1534…
wkeyDAO Exploit — Fixed-Price Presale `buy()` vs. Live AMM Price Arbitrage
Loss · ~$767 realized net (one attack tx)
WebKeyProSales is a presale contract. Calling buy() (contracts_webkey_Sales.sol:119-170) charges a fixed currentSaleInfo.price of 1,159 BUSD and immediately mints + tran…
Yzi AI (YziAI / YziLabs) Exploit — Hard-Coded `manager` Backdoor in `transferFrom`
Loss · ~376.07 BNB (≈ $222K @ ~$590/BNB) — the entire WBNB side of the YziAI/WBNB PancakeSwap po…
YziLabs is a vanilla-looking OpenZeppelin ERC20 with a booby-trapped transferFrom. The override contains a magic-number branch:
`0xD4F1…7Cb3` Exploit — Uninitialized `OwnableUpgradeable` Lets Anyone Become Owner and `withdrawFees()`
Loss · 23.00702629 BNB ≈ $15.2k (entire native balance of the contract)
The contract at 0xD4F1…7Cb3 is a PancakeSwap V2/V3 arbitrage / swap-helper bot built on OpenZeppelin's upgradeable base contracts (Initializable + OwnableUpgradeable). I…
BankX Router — `swapXSDForETH` Reentrancy (BSC focus)
Loss · ~$43K across BSC + ETH + Optimism
swapXSDForETH pulls amountInMax XSD into the pool (not the quoted amount), swaps WETH out, unwraps, and safeTransferETHs to msg.sender before burnpoolXSD(amountInMax/10).
Blend v2 — Steal other users' emissions via vulnerable claim
Untagged1. execute_claim can deposit exchanged backstop LP to a different to address. 2. It updates to's share balance without update_emissions(to). 3. A fresh to later claims w…
Bybit Cold-Wallet Heist — `DelegateCall` masterCopy Overwrite of a Gnosis Safe
Loss · ~$1.46–1.5B — 401,346.77 ETH + 8,000 mETH + 15,000 cmETH + 90,375.55 stETH drained from B…
This was not an exploit of a flaw in the Gnosis Safe contracts. The Safe behaved exactly as designed. It was a supply-chain / signing-infrastructure compromise: the atta…
Four.meme Launchpad Exploit — Liquidity Migration Front-Run via Pre-Initialized Pancake V3 Pool
Loss · ~$186K total across ~20 meme tokens. This PoC demonstrates one token (snowboard): 23.4259…
Four.meme is a "pump.fun"-style launchpad: users buy a meme token along a bonding curve, and once market cap hits a graduation threshold (~24 BNB) the platform "migrates…
GMT7 Helper permissionless drain — unverified trading bot helper exposed public buy/sell functions with no access control and infinite router approval
Loss · 16.75 BNB (~$10.1k at the time; PoC final balance 16.791444737752979201 BNB [output.txt:1…
GMT7 is a low-liquidity BEP-20 token paired with USDT on PancakeSwap (0x5317545A…3006). The project deployed an off-the-shelf "robot" helper contract (0x9AD9…31E3, unver…
GoldReserve NFT profit double-claim — ERC1155 transfer resets the per-address profit accumulator
Loss · 12.74 BNB (≈ $7.3k at the time)
GoldReserve is an ERC1155 NFT collection that distributes native-BNB "profit" to its holders. Anyone can call depositProfit{value} to push BNB into a profit pool; the po…
Hegic V8888 Put Pool Exploit — Re-withdrawable Liquidity Tranche (`withdrawWithoutHedge`)
Loss · ~$104M reported total drain of the Hegic V8888 pools; this PoC mechanically reproduces th…
HegicPool.withdrawWithoutHedge(trancheID) lets a tranche owner redeem their pool share for the underlying token. The redemption logic in _withdraw (contracts_Pool_HegicP…
HenloKart native-token drain — zero-value race commitment funded from the victim balance, then immediately cancelled back to the attacker
Loss · 0.59 ETH (reported in @KeyInfo)
HenloKart is an on-chain hamster-racing game (HenloKart) built as a UUPS-upgradeable proxy on Base. Players "commit to a race" by depositing a bet token (ETH or an ERC-2…
INVISTECH buy-tax drained the AMM pair — fee-on-transfer tax charged from the pair's own reserves on every buy, breaking the constant-product invariant
Loss · ~5.14 BNB (5.137937396574487084 WBNB net profit to attacker) [output.txt:1564-1565]
INVISTECH (INVT) is a fee-on-transfer BEP-20 on BSC paired with WBNB in a PancakeSwap V2 pool. Its custom _transfer charges a tax whenever either side of a transfer is a…
Kinetiq — Exchange rate calculation is incorrect
Untagged1. Multiple StakingManagers share one ValidatorManager (global rewards/slashing) and one kHYPE. 2. Each manager stores local totalStaked / totalClaimed. 3. getExchangeRa…
Kinetiq — Exchange rate implementation not used in token operations
Untagged1. getExchangeRatio / kHYPEToHYPE / HYPEToKHYPE implement NAV-based rates. 2. stake() still does kHYPE.mint(msg.sender, msg.value) (1:1). 3. Withdraw pays 1 HYPE per kHY…
Kinetiq — Funds can be permanently locked due to unsafe type casting
Untagged1. L1Write.sendTokenDelegate takes uint64 amount. 2. StakingManager casts uint256 → uint64 without SafeCast. 3. For amount = type(uint64).max + 1, the cast becomes 0. 4.…
Kinetiq — Some stakers may fail to withdraw staking HYPE
Untagged1. Stake path fills hypeBuffer up to targetBuffer before delegating. 2. queueWithdrawal never spends the buffer; it always undelegates from currentDelegation. 3. After a…
OpenOcean Limit Order Protocol — unrestricted `transferTokens()` drains any pre-approved maker
Loss · 2,800,000 BRAINS (victim's full balance; 2.8e24 wei / 18 decimals) — see output.txt:1624
OpenOcean's Base deployment of the Limit Order Protocol v2 is an upgradeable contract: a TransparentUpgradeableProxy (0xb5486f71…) delegates to an implementation (0xCe8D…
Optimism Interop — malicious tokens at deterministic addresses steal cross-chain funds
1. Superchain tokens are deployed through a generic CREATE2 factory that exists at the same address on every interop chain. A token's address therefore depends only on (…
Peapods Finance Exploit — Permissionless `depositFromPairedLpToken()` Forced Swap at Manipulated Spot Price
Loss · ~$3,500 — 141.11 pOHM drained from the protocol's TokenRewards contract + the pOHM/PEAS U…
Peapods TokenRewards periodically converts the paired LP token it accumulates (here pOHM) into the rewards token (PEAS) and distributes the proceeds to stakers. That con…
Recall — [H-01] Missing signature duplication check in submitCheckpoint
UntaggedSingle weight-6 validator forges majority quorum by repeating itself in signatories[]
Recall — [H-04] Overflow count of messages in bottom-up batch
UntaggedOverpopulated cut batch permanently fails ensureValidCheckpoint — bottom-up halt
Recall — [H-05] Incorrect supply fund transferral in leave()
Untaggedleave() pays genesisBalance as ETH collateral instead of supply ERC20 — drains other validators
Recall — [H-06] Reentrancy in leave() leads to halting of bottom-up checkpoints
UntaggedReentrancy via genesis ETH refund + unguarded stake() bootstraps mid-leave; confirmDeposit reverts forever
Recall — [H-07] Incorrect loop indexing in compact()
Untaggedwhile (i pending length — claimable collateral locked
Recall — [H-09] Cross msg recipient can block checkpoint submission
UntaggedUnbounded returndata from IPC recipient gas-bombs checkpoint execution under remaining gas
Roots — [H-01] Overwriting collateral breaks collateral gains logic
Untagged1. Alice accrues coll-A gains on stability-pool index 0 and leaves them unclaimed. 2. Coll A is sunset; coll C is enabled and reuses index 0. 3. Product sums for index 0…
Scorch OTC `scorch()` drains ETH via manipulated spot `getAmountsOut` quote — on-chain price manipulation in a burn-for-ETH function
Loss · ~0.14 ETH on-chain (public report); 0.337 ETH reproduced in the offline fork trace [outpu…
Scorch (OTC) is an ERC-20 whose contract holds an ETH treasury. Its scorch(amount) function lets any holder burn their OTC tokens and receive ETH directly from the contr…
StepHeroNFTs Exploit — Reentrancy in `claimReferral()` Drains the Marketplace's BNB
Loss · 137.9 BNB (~$92K at the time) net profit, drained from the marketplace contract's BNB bal…
StepHeroNFTs is an NFT marketplace that pays referral commissions in native BNB. When an NFT is sold, a fixed commission (here 3 BNB) is credited to a "referral balance"…
THORWallet — Bridge path bypasses TITN transfer lock — send to any address
UntaggedBridge path bypasses TITN transfer lock — send to any address. Harm demonstrated: Transfer-lock invariant broken: bridge credits tokens to arbitrary recipient.
THORWallet — MergeTgt has no deposit cap vs TGT_TO_EXCHANGE — late claimers stuck
UntaggedMergeTgt has no deposit cap vs TGT_TO_EXCHANGE — late claimers stuck. Harm demonstrated: Over-subscribed TGT deposits leave late claimers unable to redeem TITN.
Treasury Vesting — `batchRelease` updates state before transfer, users get nothing
1. Loop 1: for each user, compute releasable, add to userReleased / totalReleased. 2. Loop 2: recompute releasable — now 0 because loop 1 already credited releases — ski…
Unverified "Slot" Staking Contract — `releaseSlot()` Reentrancy BNB Drain
Loss · ~$6,700 — 10.2 BNB drained from the contract's native balance (attacker walked off with 1…
The contract is a BNB "slot" staking / lottery product. A user calls unlockSlot(uint256) with BNB to activate a slot, and later calls releaseSlot(uint256) to get their d…
Venus (zkSync Era) Exploit — wUSDM ERC4626 Donation → Oracle Price Inflation → Self-Liquidation Drain
Loss · 86.72 WETH ≈ $201,600 extracted by the attacker (paid as a Venus self-liquidation drain).…
Venus's zkSync deployment listed wUSDM (an ERC4626 wrapper over the USDM stablecoin) as a market. wUSDM's USD price is computed by Venus's ERC4626Oracle, which simply re…
98Token ("98#") Exploit — Unprotected `public swapTokensForTokens()` Drains the Contract's Token Reserve
Loss · ~$28K — 27,995.39 USDT swept out of the USDT/98# PancakeSwap pair
The Main contract is a "car-racing / guild" GameFi app whose reward token is 98#. To run its game economy it embeds thin wrappers around the PancakeSwap router and, in i…
Abacus clearUnusedBond drains credits — AuditVault 48699
clearUnusedBond lacks the bond-owner restriction and can erase all outstanding credit bonds.
Abacus past-closure adjustment bypass — AuditVault 48701
adjustTicketInfo does not reject a ticket whose closure has already been finalized.
Abacus tokenMapping inconsistency — AuditVault 48698
The registration path writes tokenMapping but updates a different existence key, so lookups disagree.
Abacus transferFrom drops locked ether — AuditVault 48700
Position ownership moves without moving the corresponding ethLocked amount.
AI IPC Token Exploit — Sell-Triggered Pool Burn (`_destroy`) Drains the AMM Reserve
Loss · ~591,933 USDT (~$590K) drained from the IPC/USDT PancakeSwap pair
Token ("AI IPC") is a deflationary token with a "destroy → reproduce" mechanic. On every sell (an IPC transfer into the IPC/USDT pair), the token's _transfer hook calls…
AIXBT Forced-Swap Exploit — Public "Auth-Key" Selector Swaps Victim's Whole Balance into Attacker LP
Loss · 13,598.795675 USDC (13,598,795,675 raw, 6-dec) drained from the victim — tx 0x5a7462b79d6…
1. The victim contract 0x32cD8541… exposes a public function with selector 0x229e9756 that, when called with the right key, approves its entire token balance to the Unis…
Any attempt to liquidate a user will fail — StabilityPool never holds crvUSD
Untagged1. Operational deposits route crvUSD into the reserve, never into the StabilityPool. 2. A borrower has outstanding debt and should be liquidatable. 3. liquidateBorrower…
AST Token Exploit — Faulty `transfer` Liquidity-Tracking Burns Pool Reserves Twice
Loss · ~$65,000 — 65,145 BUSD drained from the BUSD/AST PancakeSwap pair
AST is a fee-on-transfer token that tries to detect liquidity adds/removes by watching balances inside its own _transfer hook. The detection logic is broken in two compo…
Burve SimplexDiamond — Unrestricted `diamondCut` allows unauthorized facet modifications
Untagged1. SimplexDiamond exposes diamondCut without AdminLib.validateOwner() (or any auth). 2. Any address can add/replace/remove facet selectors. 3. Attacker adds a drain face…
collect() trusts an arbitrary DAO contract — AuditVault synthetic reduction
The report describes a high-risk bug in the DaosLocker::collect() function, which can be exploited by a malicious actor to steal swap fees from legitimate DAOs. This can…
DESK / HMX — Incorrect margin calculation due to inconsistent realized and unrealized balances
1. Liquidation margin = getSubaccountTotalMargin (realized, CF already applied) + unsettled PnL. 2. Unsettled PnL only gets the collateral factor when positive; negative…
Etherspot CredibleAccountModule — [H-01] no check for `userOp` / `userOpHash` mismatch nor sender validity
Untagged1. validateUserOp(userOp, userOpHash) derives sessionKeySigner from userOpHash and validates params against userOp. 2. There is no check that userOp.sender == msg.sender…
Etherspot CredibleAccountModule — session owner can consume a sibling session
The module verifies that a signer belongs to the smart wallet but never checks that the session named in claim() is the same signer. One active session key can therefore…
Etherspot CredibleAccountModule — session-key approval drains the wallet
Session-key call validation allows any ERC20 approve target. The key owner chooses itself as spender, then calls transferFrom to remove every token held by the smart wal…
Etherspot GasTankPaymaster — user withdraws before sponsored gas repayment
postOp records a user's gas debt, but withdraw remains unrestricted. The user can empty the GasTank before the asynchronous repayment job runs, leaving the paymaster una…
Etherspot ResourceLockValidator — replayable signature proof
The validator checks a ResourceLock Merkle proof but never consumes it. EntryPoint can therefore submit the same call data with a different nonce, and the wallet execute…
EYWA EscrowManager reentrancy — AuditVault 44334
Escrow performs the external receiver callback before its accounting transition, allowing nested withdrawals.
EYWA EscrowVoteManager poke DoS — AuditVault 44337
poke accepts a token ID owned by another account and lets an untrusted caller poison vote state.
Folks Finance borrow balance omits interest — AuditVault 61079
getLoanLiquidity reports only principal and drops accrued interest from the borrow balance.
Folks Finance loan-health underestimation — AuditVault 61051
The health calculation overstates collateral capacity and permits an outsized loan for a minimal deposit.
Folks Finance mixes stable and variable debt — AuditVault 61091
Liquidation merges stable debt into the variable bucket, changing the borrower’s debt semantics.
HORS Exploit — Unprotected, Attacker-Callback `0xf78283c7` Drains the Pool's LP Tokens
Loss · 14.799349453861436868 WBNB (~$10.4K at ~$700/BNB on the day) — the entire HORS/WBNB liqui…
The HORS project deployed a helper contract at 0x6f3390…eaba that custodied the LP tokens of the HORS/WBNB PancakeSwap v2 pair. That contract exposes a function with sel…
IPSeed tokenId reconfiguration drain — AuditVault 31585
A caller can reconfigure tokenId and withdraw ETH belonging to the previously configured asset.
IQ AI — Adversary can win proposals with voting power as low as 4%
Untagged1. Constructor sets GovernorVotesQuorumFraction(4) with comment "quorum is 25% (1/4th)". 2. OZ quorumDenominator() defaults to 100, so quorum = supply * 4 / 100 = 4%. 3.…
JPulsepot / FortuneWheel Exploit — Permissionless `swapProfitFees()` + Spot-Price Fee Sizing
Loss · ~$21.5K — 30.968 WBNB profit, extracted from the FortuneWheel casino's accumulated fees /…
FortuneWheel is an on-chain casino. House profit accumulates per game in various tokens. A maintenance routine, swapProfitFees() (contracts_FortuneWheel_FortuneWheel.sol…
Karak increaseBalance share loss — AuditVault 38492
increaseBalance rounds the minted share amount down by a factor of two.
LAURA Token Exploit — Permissionless `removeLiquidityWhenKIncreases()` Reserve Burn
Loss · 12.340357077284305206 ETH (~$41.2K) drained from the LAURA/WETH Uniswap-V2 pair
LAURA (deployed by a pump.fun-style launchpad as a PumpToken) has a public, unprotected function removeLiquidityWhenKIncreases(). It reads the LAURA/WETH pair's reserves…
Liquid Ron — totalAssets wrong when operatorFeeAmount > 0
Untagged1. Operator fee sits in the vault balance and is tracked in operatorFeeAmount. 2. totalAssets() still counts that fee toward share pricing. 3. New depositor mints fewer…
LPMine Exploit — Reward-Time Desync + Pool-Balance Reward Valuation Drains the Reward Pool
Loss · ~$24k — net +23,293.95 USDT to the attacker; the LPMine reward pool was drained of ≈402.2…
LPMine is a "stake-LP, earn-tokens" farm. A staker's claimable reward is computed in getCanClaimed() as
MCAI tax-wallet allowance bypass — privileged `transferFrom` drains the Uniswap V2 pair
Loss · ~12.03 WETH / ETH (12.028506355387210510 ETH extracted by the attacker EOA)
Memecast AI (MCAI) is a generic fee-on-transfer meme token with a Uniswap V2 MCAI/WETH pool. Its ERC-20 transferFrom does not enforce the spender allowance in the normal…
Mismatching data location during inheritance — AuditVault 50685
The inherited handler stores a calldata payload through an incompatible data-location boundary.
Mosca Exploit — `exitProgram()` Pays Out Internal Credit That Was Never Backed by a Deposit
Loss · ~$19K combined — both stablecoin sides of the contract were drained. The PoC's USDC-only…
Mosca is an MLM-style "citizenship" program that keeps per-user internal balances in three fields — balance (MOSCA credit), balanceUSDT, balanceUSDC (Mosca.sol:175-187).…
Mosca Exploit — Self-Compounding `join()` Balance Inflation Drains the Treasury
Loss · ~$37.6K — 11,395.25 BUSD + 26,254.20 USDC drained from the Mosca contract
Mosca is an on-chain MLM / "membership" program. Members join() by paying USDT (BUSD on BSC) or USDC, in exchange for an internal credit (users[me].balance) that they ca…
Next Generation — Cross-chain signature replay via user-supplied domainSeparator
Untagged_verifySig takes domainSeparator from the caller. Two chain deployments both accept the same domain label; independent nonces allow draining EURF on each chain under tha…
Notional v4 — redeemNative reentrancy freezes yield tokens
UntaggedredeemNative snapshots balance, swaps via a path including a malicious token that reenters initiateWithdraw (moves N yield tokens and decrements accounting). After retur…
Odos Limit Order Router Exploit — Public ERC-6492 `isValidSigImpl(... allowSideEffects = true)` Arbitrary-Call Drain
Loss · 15,578.334373 USDC (≈ $15.6K) drained from the router; total campaign across chains repor…
The Odos limit-order router inherits the Ambire UniversalSigValidator implementation of ERC-6492 ("Signature Validation for Predeploy Contracts"). ERC-6492 lets a not-ye…
OpenTrade rollover loan-address validation — AuditVault 47890
The rollover entry point accepts an arbitrary loan address instead of validating pool ownership.
Paribus Exploit — Algebra/Camelot LP-NFT Collateral Priced from Manipulable Spot Price
Loss · ~$86K — borrowed assets (ETH + ARB + WBTC + USDT) drained from the Paribus lending market…
Paribus is a Compound-fork lending protocol on Arbitrum that, beyond ordinary ERC-20 markets, accepts concentrated-liquidity LP NFTs (Camelot/Algebra V1 and Uniswap V3 p…
Predictable token address enables liquidity front-run — AuditVault synthetic reduction
This report describes a high-risk bug that allows an attacker to manipulate the deployment of a contract called DaosToken within the DaosLive contract. This predictabili…
Prime Vaults — removed strategy remains callable during withdrawal
removeStrategy deletes a struct, resetting kind to SingleAsset and active to false. PrimeStrategy ignores active, so its withdrawal queue still calls the removed strateg…
PufferVault partial withdrawal failure — AuditVault 38286
A partial failure returns early and silently leaves later withdrawal requests unhandled.
Pyth price and exponent mismatch — AuditVault 51982
A negative Pyth price is converted to an unsigned reported value while the signed stored value remains negative.
Pyth validation is not payable — AuditVault 51984
The update function is non-payable, so a caller cannot forward the provider fee.
Reduced plugin price leaves excess payment trapped — AuditVault synthetic reduction
The report discusses a bug in the Multicall contract where the click() function does not properly check the msg.value sent by users. This can lead to a vulnerability whe…
RoulettePotV2 Exploit — Permissionless `swapProfitFees()` Drained Through a Manipulated WBNB/LINK Spot Price
Loss · 39.52 WBNB ≈ $27.7K (reported ~$28K) — extracted from the WBNB/LINK PancakeSwap V2 pool
RoulettePotV2.swapProfitFees() is a permissionless maintenance function that converts the casino's accumulated profit/fee tokens into BNB, then buys Chainlink LINK with…
Session key can be consumed by another smart wallet — AuditVault synthetic reduction
The bug report describes an issue with the CredibleAccountModule contract, where there is a lack of check to verify that the session key being used belongs to the actual…
Shiny Pawn — off-chain offer amount creates underwater loans
Pawn trusts a backend-signed offerAmount without checking collateral value on-chain, then permits liquidation only after a deadline. A price drop during the term creates…
Shiny sRWA — blacklisted operators cannot be revoked and can steal NFTs
UntaggedsetApprovalForAll reverts on blacklisted operator even for approved=false; approve still usable by blacklisted operators
Sorra Staking Exploit — Reward Recomputed In Full On Every Partial `withdraw`
UntaggedLoss · ~8 ETH across the victim's three deposit/attack cycles (PoC header: 4.8 + 2.4 + 0.8 ETH).…
sorraStaking lets a user stake SOR in a tier (tier 0 = 14-day lock, 5% reward) and later withdraw(_amount) their principal plus a vesting reward. The reward is computed…
Stake.Link — instant withdrawals can burn LST while stranding underlying
During an instant withdrawal, PriorityPool receives underlying assets from StakingPool and reduces toWithdraw, but it never increments withdrawn. StakingProxy has alread…
Surge — [H-03] Unstake causes all users to lose their rewards
Untagged1. User and attacker each stake 1000 into cycle 1 (total shares = 2000). 2. Rewards are injected for the cycle. 3. Attacker unstakes; _unstake reads total pool shares an…
Switchboard reward manipulation — AuditVault 47980
Reward accounting remains writable after an enclave update and has no authorized caller check.
The Idols NFT Exploit — Self-Transfer Reward Double-Claim via `delete claimedSnapshots`
Loss · 97 stETH total across ~15 repeated transactions (~$329K at the time). This PoC reproduces…
IdolMain is an NFT ("god") that streams stETH rewards to its holders. It tracks a global cumulative reward index rewardPerGod and, per holder, a claimedSnapshots[addr] w…
Toki Bridge — malformed recipient bytes silently burn tokens
The bridge accepts any non-empty recipient bytes, but the destination decoder accepts only 20-byte EVM addresses. Decode failure enters an unrecoverable branch without a…
UniLend V2 Exploit — Collateral Self-Withdrawal via Flawed Health-Factor Accounting
Loss · ~60.67 stETH (≈ $200K at the time) — the entire stETH liquidity of the USDC/stETH pool
UniLend V2 is an isolated-pair money market. Each pool holds two assets — here token0 = USDC, token1 = stETH. A user's position (an NFT) can simultaneously lend one asse…
USDT claim underflows when contract has a larger balance — AuditVault synthetic reduction
This bug report describes a high-risk issue in the claimRewards function of the VestedStaking.sol contract. The issue affects the calculation of USDT rewards and can be…
Zero-value transfer doubles staking rewards — AuditVault synthetic reduction
The report details a critical bug in the _claimToCredit() function of the StakedCSX.sol contract. This function has a logical error where the addition assignment operato…
Bizness Locker Exploit — Reentrancy in `splitLock` Refund Drains Locked Tokens
Loss · ~$15.7k — 4,412,545.597 BIZNESS double-claimed out of the shared Locker vault
The Bizness Locker lets anyone lock ERC20/NFT tokens until an unlockTime. splitLock is supposed to carve a portion of an existing lock into a new lock. But splitLock cha…
BTC24H `Lock` Exploit — Access-Control-Free `claim()` Drains a Token Vesting Lock
Loss · ~$85.7K — 4,953.03 USDT + 0.76433345 WBTC drained from two BTC24H Uniswap-V3 pools
Lock is a one-shot token-vesting contract that holds 110,000 BTC24H to be released to a beneficiary on Dec 15, 2024 (releaseDate = 1734220800). The release function is:
Clober DEX Exploit — `Rebalancer._burn` Reentrancy via Attacker-Controlled `burnHook`
Loss · ~$501K — 133.71 WETH drained from the Clober Rebalancer vault
Clober's Rebalancer is an LP-vault that wraps two Clober order-books. When you burn() your LP shares it computes your payout from the pool reserves, burns your shares, c…
Cork — Attacker can perform MEV by providing amountOutMin = 0 for ERC-2612 permit swaps
Untagged1. User signs an EIP-2612 permit so the router can pull RA without a prior approve tx. 2. Any third party can submit that permit to swapRaforDs(..., amountOutMin, user,…
Cork — Insufficient slippage protection in `redeemEarlyLv` leads to MEV via flash swaps
Untagged1. redeemEarlyLv takes amountOutMin and checks it only against RA from the AMM. 2. CT / DS / PA received have no floors. 3. Attacker skews the RA/CT pool (e.g. flash-sty…
Cork — Reserve sales vulnerable to MEV due to missing slippage protection in `_sellDsReserve`
Untagged1. User RA→DS swaps can trigger a protocol reserve sale of DS for RA. 2. _sellDsReserve calls the swap with hardcoded amountOutMin = 0. 3. An MEV bot dumps DS into the p…
FEG SmartBridge — Wormhole relayer allowlist pollution → forged withdraw
Loss · ~$1M+ multi-chain (ETH ~96 ETH, Base ~73 ETH, BSC ~712 BNB after dump)
FEG’s Wormhole-based SmartBridge only lets the relayer call registerWithdraw. The relayer maintained a sourceAddress allowlist but updated that allowlist from bridge mes…
GemPadLock reentrancy (Dec 2024) — multi-chain ~$2M
UntaggedLoss · ~$1.9–2.2M locked LP / ERC20 inventory
JHY Token Exploit — Dividend Pool Drained via 100× Over-Credited `distributeCAKEDividends`
Loss · ~$11.2k — 11,231.38 BSC-USD (USDT) extracted (started with 26.54, ended with 11,231.38)
JHYToken charges a 3% tax on every sell into the Pancake pair: 2% burned to dead, 1% sent to a "dividend tracker" (dividendLPTracker, the DIVIDEND_JHYLP contract) so LP…
LABUBU Exploit — Self-Transfer Balance Inflation via Stale Cached Balances
Loss · 17.40 BNB (~$12,048) — drained from the VOVO/wBNB PancakeSwap V2 pair
LABUBU's _transfer (LABUBU.sol:119-141) reads both the sender's and the recipient's balance into local variables at the top of the function, then writes them back indepe…
MoonHacker Vault Exploit — Unauthenticated AAVE Flash-Loan Callback Drains the Vault
Loss · ~$318.9K total across the attacker's full campaign; 109,386.69 USDC drained from the mUSD…
MoonHacker is a "smart leverage" helper vault that wraps Moonwell (a Compound-fork lending market) positions behind AAVE V3 flash loans. The vault's AAVE callback, execu…
NFTMirror — Anyone can re-mint a token that was burned by the owner
Untagged1. Non-existent tokens default to locked, so only the beacon can mint them. 2. Owner can burn an unlocked token; burn does not set lock state back to locked. 3. After bu…
NFTMirror — lzReceive for releaseOnEid results in OOG
Untagged1. releaseOnEid builds LZ options via getSendOptions(tokenIds). 2. Budget = 80_000 + 20_000 * length — too low for destination mint/transfer (and worse with transfer val…
Non-payable batch sender blocks result submissions — AuditVault synthetic reduction
This bug report discusses an issue with the SEDA protocol that allows an attacker to exploit the batch sender role and block result submissions by using a contract that…
Pledge Exploit — Permissionless `swapTokenU()` Drains the Contract's Token Holdings
Loss · ~$15K — 14,994.30 USDT swapped out to the attacker
Pledge is a staking/referral ("pledge") front-end contract that holds a large balance of its own project token, MFT. To convert its MFT holdings into USDT it exposes a h…
SlurpyCoin Exploit — Attacker-Timed Token-Owned `BuyOrSell` Pool Manipulation
Loss · ~$3K (reported). PoC nets 7.4118 BNB of pool WBNB, intra-transaction, off a 40 WBNB flash…
SlurpyCoin is a "reflection + auto-liquidity" meme token. Its _transfer hook contains a BuyOrSell() routine (SlurpyCoin.sol:1123-1138) that fires automatically whenever…
Solady — `isValidERC6492SignatureNowAllowSideEffects` allows arbitrary calls via a crafted signature
1. ERC-6492 lets a signature be postfixed with a magic suffix so a verifier can "prepare" (deploy) a smart-account signer before doing the ERC-1271 check. 2. Solady's Al…
Validator proof duplication bypasses consensus — AuditVault synthetic reduction
This bug report discusses a critical security issue with the SEDA protocol's cross-chain data verification system. The issue was discovered by a group of researchers and…
0x Protocol "Settler" Exploit — Arbitrary External Call via `BASIC` Action Drains a Leftover Approval
Loss · ~$66,000 — 308,453,642.48 "Hold" (EVERYBODY) tokens drained from a single victim
0x Protocol's Settler is a swap router whose execute() entry point runs a list of "actions". One of those actions, BASIC, is a generic "call this pool with this data" pr…
AkashaOFT (AK1111) Exploit — Permissionless `nonblockingLzReceive1()` Free-Mint Backdoor
Loss · ~15,907.5 USDT drained from the AK1111/USDT PancakeSwap pair in this single PoC tx (incid…
AkashaOFT is a LayerZero OFT v1 (Omnichain Fungible Token) where new supply is normally minted only when a cross-chain message arrives through the LayerZero endpoint. Th…
Autonomint — `ABONDToken::transferFrom` corrupts `userStates` and enables Treasury ETH theft
1. transferFrom debits the from State, then writes it to msg.sender. 2. The true from keeps their full ethBacked State; the spender inherits a quasi-copy of the rich Sta…
Autonomint cross-chain price desync — AuditVault 45459
lastEthPrice is updated on one chain without synchronizing the other chain.
Autonomint downsideProtected DoS — AuditVault 45461
An attacker can set downsideProtected so settlement underflows and the protocol is permanently unavailable.
Autonomint excess profit withdrawal — AuditVault 45458
The cumulative profit value is not consumed, so CDS owners can withdraw it repeatedly.
Autonomint odos data manipulation — AuditVault 45457
The assembled Odos payload is trusted without checking its amount or route.
Autonomint redeemYields accounting — AuditVault 45456
The caller’s ABOND is debited while redemption state is credited to a different user.
Autonomint withdrawUser deduction — AuditVault 45460
withdrawUser deducts one tenth of the user’s deposit instead of the full amount.
Autonomint: a lossy CDS withdrawal corrupts totalCdsDepositedAmount
UntaggedAutonomint: a Type-2 liquidated borrower can still withdraw its collateral
UntaggedAutonomint: borrower downside protection is recovered into the whole CDS pool
UntaggedBracket receives unlimited StopLimit allowance — AuditVault synthetic reduction
This bug report discusses a vulnerability found in a contract called "StopLimit". The issue was discovered by a group of individuals and can be exploited by an attacker…
ChiSale Exploit — Revenue-Share Computed on Full `msg.value` (Self-Referral ETH Drain)
Loss · ~$16.3k — 5.78078 ETH drained from the ChiSale contract's ETH reserves
ChiSale.buy() is a 2018-era token-sale contract. A buyer sends ETH; the contract gives out tokensToBuy = msg.value / 0.001 ETH CHI, refunds any unused ETH, and pays a 22…
CoW Protocol Solver-Router Exploit — Unvalidated `uniswapV3SwapCallback` Drains Settlement's Residual WETH
Loss · 5.373296932158610028 WETH drained from the GPv2Settlement contract (PoC-verified). The De…
A solver in CoW Protocol is an externally-operated agent that fills user orders by routing them through AMMs (Uniswap, Pancake, etc.). To do that, the GPv2Settlement con…
DeltaPrime Exploit — Unwhitelisted `claimReward()` Pair + Cross-Function Reentrancy Drains a SmartLoan's Borrowed Funds as "Reward"
Loss · 66.6195 WETH per loop drained from a DeltaPrime lending pool in the reproduced tx (≈ $211…
A DeltaPrime SmartLoan is an isolated borrowing account (a beacon proxy) with a TraderJoe-V2 integration facet. Its claimReward(ILBPair pair, uint256[] ids) function is…
ERC1967Proxy (0xb7E1…) Exploit — Unauthenticated "Order Settlement" Drains Proxy Reserves
Loss · ~$8.5k — 8,484.92 BEP20-USDT drained from the proxy, sold for 13.04 BNB
The contract at 0xb7E1… is an upgradeable order/escrow contract (an "order" data structure with a monotonic nextOrderId, per-order bytes32 payload, and a receipt/share t…
Matez Staking Exploit — `uint128` Truncation Lets Anyone Stake "for Free"
Loss · ~$80,000 — the staking contract pays out reward tokens it should never have owed
MatezStakingProgram.stake(uint256 amnt) is supposed to pull amnt-worth of deposit tokens from the user and credit them with an investment of amnt. But it computes the am…
MFT Token Exploit — Burn-on-Sell `sync()` Drains the PancakeSwap Pair
Loss · ~$33.7k — 33,695.36 USDT (BSC-USD) net profit drained from the MFT/USDT PancakeSwap pair
MFT is a "fee-on-transfer + auto-nuke-LP" meme token. On every sell into the pair, while a launch window is open (block.timestamp < _startTime1), _tokenTransfer calls bu…
NFTG Presale Exploit — Mispriced `PresaleWithUSDT()` Pays ~13× the USDT Deposited
Loss · ~$10,044 — 10,044.49 BEP20-USDT drained from the presale contract
The NFTG presale contract exposes a public function PresaleWithUSDT(uint256 amount, address recipient) (selector 0x85d07203). The intended flow is "deposit USDT, receive…
Oku — Failure to reset unspent approval to the target address wipes the contract balance
1. execute approves an arbitrary target for the full order.amountIn. 2. The target call need only move 1 wei of tokenIn / tokenOut to pass the minAmountOut / over-spend…
Oku OracleLess: `procureTokens` pulls from the order recipient, letting an attacker steal a victim's approved tokens
Oku OracleLess: a cancelled order can be modified to withdraw its escrow twice
OracleLess executes attacker-controlled target — AuditVault synthetic reduction
The OracleLess contract has a vulnerability that allows attackers to drain all USDT from the contract. This is caused by the createOrder() function not verifying if the…
Order fill/modify reentrancy steals collateral — AuditVault synthetic reduction
This bug report highlights an issue with the lack of a certain modifier in the code, which can allow an attacker to steal funds from the victim. The report explains the…
Polter Finance Exploit — Spot-Reserve Price Oracle Manipulation Drains an Aave-V2 Lending Market
UntaggedLoss · ~$7M — attacker borrowed out the entire lending market against 1 BOO of "collateral". Thi…
Polter Finance is an Aave-V2 fork lending market on Fantom that accepted SpookySwap's BOO as a collateral asset. Its price oracle for BOO derived the BOO price from the…
Primev — Overpayment to bidder in `slash` due to incorrect amount transfer
1. slash computes residualAmt = amt * residualBidPercentAfterDecay / 100%. 2. Provider stake is reduced by residualAmt + fee (correct). 3. Bidder is paid amt instead of…
RichPip (RPP) Token Exploit — Sell-Triggered LP Burn Pumps a Self-Manipulated Pool
Loss · +9,718.11 USDT profit reproduced in-fork (header reports total loss ≈ $14.1K)
RichPipToken is a deflationary token whose sell path runs _burnLpsToken(amount). That routine burns 2.06 × amount of RPP directly out of the AMM pair's balance and then…
Stake319 (X319) Exploit — Permissionless `claimEther()` drains the contract's BNB
Loss · 20.85 BNB ≈ $12.9k — 100% of the BNB held by the token contract
Stake319 is a BSC token that, at the time of the hack, held 20.85 BNB as its own native balance. It exposes a function claimEther(address receiver, uint256 amount) whose…
Superfluid Locking — `Fontaine` never stops flows; deposit buffer is permanently lost
1. Superfluid reserves 4 hours of flow rate as a deposit buffer when a flow opens. 2. Fontaine.initialize opens a tax distributeFlow and a recipient createFlow. 3. There…
Sweep n Flip — LayerZeroAdapter.executeMessages irrecoverable state
1. Failed LZ deliveries are stored in s_pendingMessagesToExecute. 2. executeMessages runs pending[0] but pop() removes the last element. 3. With [msg1, msg2]: first call…
Sweep n Flip — Premature createPair creates unusable delegated pairs
1. Wrapper addresses for ERC721 collections are CREATE2-predictable from the factory. 2. Ideal flow is createWrapper then createPair. An attacker can call createPair(usd…
Sweep n Flip Bridge — Permanent failure to bridge wrapped ERC721
1. Bridging an origin NFT locks it on the source bridge and mints a wrap on the destination. 2. Reverse-bridging the wrap must read metadata from the wrap (which exists…
uint256 amount truncates to uint160 — AuditVault synthetic reduction
This bug report discusses an issue found in the rotocol's handling of token amounts. The contracts use unsafe type casting from uint256 to uint160, which can lead to sil…
vETH (Lambo.win) Exploit — Unbacked `takeLoan` via `addVirtualLiquidity` Inflates an AMM Pair
Loss · ~$447K total across 3 attackers; this PoC reproduces the vETH-BIF leg = 132.51 ETH profit…
Lambo.win's VirtualToken ("vETH") exposes a privileged takeLoan(to, amount) (src_VirtualToken.sol:90-102) that mints brand-new vETH out of thin air — _mint(to, amount) —…
VRUG ("Vitalik's Rug") Exploit — Unsynced UniswapV2 Reserve Donation Harvest
Loss · ~$8.4K — 2.9038726878518077 WETH harvested out of the VRUG/WETH pair
Someone (the VRUG deployer / a holder) transferred 850,000,000 VRUG directly into the VRUG/WETH UniswapV2 pair without calling sync() or trading through it. A UniswapV2…
AIZPT314 Exploit — ERC-314 "Buy Mints 2× From Reserve" Price-Skew Drain
Loss · 34.88564338 WBNB (~$20K USD at the time) drained from the AIZPT314 token's own liquidity
AIZPT314 is an ERC-314 "no-router AMM" token: the token is its own liquidity pool. You send it BNB via receive() and it mints/transfers you tokens (buy); you transfer to…
AXION buyback liquidity burn — AuditVault 43530
The V3AMO buyback uses a spot-derived amount and burns ten times the requested liquidity.
CompoundFork (Pike Finance "uSUI") Exploit — Spot-Price Oracle Manipulation of a Compound v2 Fork
UntaggedLoss · ~$1M total protocol drain; the reproduced WETH leg = 256.05 WETH (≈ $632K @ ~$2,470/ETH)
A Compound-v2 fork on Base (the "Pike"/uSUI markets) priced its uSUI collateral via a custom price feed 0xc112…7e0c that reads the instantaneous slot0().sqrtPriceX96 of…
Erc20transfer Exploit — Permissionless Arbitrary `transferFrom` Drainer (`amount==0` ⇒ "take it all")
Loss · $14,773.35 — 14,773.35 USDC drained from one victim wallet
0x43Dc865E… is a public "transfer helper" contract that exposes erc20TransferFrom(address token, address to, address from, uint256 amount) with no access control whatsoe…
FireToken Exploit — Deflationary "burn-from-pool + sync()" AMM Reserve Drain
Loss · 8.4556 WETH (~$20K USD) — drained from the FIRE/WETH Uniswap-V2 pair
FireToken advertises itself as an "ultra-hyper-deflationary token … Every time a sell occurs, 100% of the tokens sold are automatically transferred from the liquidity po…
HYDT Protocol Exploit — Spot-Reserve Oracle Lets `initialMint()` Print HYDT at a Manipulated BNB/USD Price
Loss · ~$5,800 USDT (TenArmor / BlockSec figure). Reproduced net profit in this PoC: 5,702.55 US…
HYDT is a USD-pegged stablecoin. Its InitialMintV2.initialMint() lets anyone send BNB and receive HYDT "at 1 HYDT per USD at current BNB/USD rates". The "current BNB/USD…
Lava Lending Exploit — Flash-Inflated Uniswap-V3-LP Collateral Drains an Aave-V2 Fork
Loss · ~$131.8K — 1 USDC, 125,795.6 USDC (cUSDC reserve), 0.00679 WBTC, 2.25 WETH
Lava Lending is an Aave-V2 fork that accepts a fungible wrapper token for a Uniswap-V3 WETH/USDC position (WETHUSDC_LP, 0x6700…) as collateral. The lending pool values t…
MorphoBlue PAXG/USDC Market Exploit — Misconfigured Oracle (1e12 Decimal-Scale Error)
Loss · 229,644.22 USDC (~$230,000) borrowed out of the PAXG/USDC Morpho Blue market and never re…
A new Morpho Blue isolated market PAXG (collateral) / USDC (loan) was created with a MorphoChainlinkOracleV2 instance whose immutable SCALE_FACTOR was computed in the co…
Ora AI (ORAAI) Exploit — Permissionless `stuckToken()` Allowance Grant Drains the Uniswap Pair
Loss · 45.93 WETH (~$131K) drained from the ORAAI/WETH Uniswap V2 pair
ORAAI ships a function that looks like a benign "rescue stuck tokens" helper:
P719 Token Exploit — Sell Price Inflated by an Un-Compensated Burn Inside `transfer()`
Loss · 547.18 BNB (~$312K) drained from the P719 token's internal BNB reserve
P719 is a "tax + burn" token that doubles as its own decentralized exchange. Sending BNB to the contract acts as a buy (it mints P719 and hands most of it to the buyer),…
Sablier Flow — Sender can brick a stream by forcing an overflow in the debt calculation
1. Sablier Flow streams tokens continuously based on a per-second rate, ratePerSecond, chosen entirely by the stream's sender at creation (or via adjustRatePerSecond). 2…
SASHA Token Exploit — Draining a Deployer-Seeded, Massively Mispriced Uniswap V3 Pool
Loss · ~249.28 WETH (~$600K) drained from the SASHA/WETH Uniswap V3 pool
There were two SASHA/WETH liquidity pools on-chain priced more than a million times apart:
Vista Finance Exploit — Flash-Mint Burns Through the Staking Lock to Sell Free Collateral
Loss · ~29,000 USDT (PoC nets 32,720.67 USDT at the fork block) drained from the Vista "sell/buy…
VistaFinance is an ERC20FlashMint token that also enforces a staking lock: transfer and transferFrom revert unless the caller's free balance (balanceOf − sumOfActiveStak…
`0x16D0…` Exploit — Permissionless `multiCallWithRevert` Arbitrary-Call Allowance Drain
UntaggedLoss · 329.455616 USDT ≈ $329 — the victim's entire USDT balance
The contract at 0x16D0… exposes a fully permissionless function multiCallWithRevert(address token, bytes[] data). For each entry in data, it executes token.call(data[i])…
0x71cd Swap-Helper Exploit — Permissionless `pancakeV3SwapCallback` Drains a Pre-Approved Victim
Loss · ~$100 — 0.18416 WBNB pulled from the victim's pre-approved WBNB allowance
The contract at 0x71cd31a5… is a small swap-helper / router-like contract that exposes a public pancakeV3SwapCallback(int256 amount0Delta, int256 amount1Delta, bytes dat…
AIRBTC Exploit — Permissionless `done()` Token-Sweep Drain of a Helper Contract
Loss · ~$6.8k — 6,818.14 BSC-USD drained from the AIRBTC/BSC-USD PancakeSwap pair
The helper contract 0x12050… (unverified, AIRBTC-related, owner() = 0xff3F3A…) held a huge balance of AIRBTC tokens — 1,009,907,600,196,326,551,673,167,843 wei (≈ 1.01e9…
Bankroll Network Stack Exploit — Self-Buy Dividend Inflation via `buyFor(bankRoll, …)`
Loss · ~404.46 WBNB net profit (≈ 412.46 WBNB drained from the BankrollNetworkStack contract)
BankrollNetworkStack is a "dividend / staking pool" token (a TRX/ETH-clone "dapp" contract). Every purchase pays a 10% entry fee, and one-fifth of that fee is paid out i…
Bedrock DeFi (uniBTC) Exploit — `mint()` Prices Native ETH 1:1 as Native BTC
Loss · ~$1.7M total during the incident; this PoC reproduces a single flash-loan round netting 6…
Bedrock's Vault.mint() payable function mints uniBTC (a 1:1 BTC-pegged token, 8 decimals) in exchange for the chain's native coin, treating msg.value as if it were nativ…
Caterpillar Coin (CUT) Exploit — LP-Removal "Value Preservation" Mints Free Tokens
Loss · ~$1.26M — 1,260,378 BUSD net profit drained from the BUSD/CUT PancakeSwap pool (PoC heade…
CUT (token name CUT, but the verified contract is named BEP20USDT) is a "DeFi marketing token" that overloads _transfer with bespoke buy/sell/add-LP/remove-LP behaviors,…
DOGGO Exploit — Attacker-Triggered Tax Auto-Sell Self-Sandwich
Loss · ~$7K — net 2.7177 ETH extracted by the attacker in one transaction
DOGGO is a Uniswap-style meme token with an "auto-swap the accumulated sell tax to ETH" feature. Inside every transfer it checks whether its own DOGGO balance has crosse…
HANA Token Exploit — Tax-Swap Self-Dump Price Manipulation via Forced Auto-Sell
Loss · ~$283 — 0.10833 ETH extracted by the attacker EOA
HANA is a Shib-style "tax token." On every sell it can auto-liquidate its own accumulated tax tokens — but the routine swapTokensForEth(...) (HANA.sol:310-322) sells tho…
INUMI Exploit — Unprotected `setMarketingWallet()` Hijacks the `rescueEth()` Recipient
Loss · ~$11,000 — 5.0 ETH drained from the INUMI token contract
The INUMI token contract has two privileged-looking maintenance functions:
MARA (MaraToken) Exploit — Permissionless Mint via an Unprotected "Buy" Proxy that is a Token Keeper
Loss · ~8.8 WBNB (≈ \$4.8K at ~\$550/BNB, Sep 2024) — drained from the MARA/WBNB PancakeSwap pair
MaraToken exposes a privileged mint function, releaseTokenFromEventOfProject(amount, _to, _mode), guarded only by require(_onlyKeeper[msg.sender]) (MaraToken.sol:704-712…
Onyx Protocol (OnyxDAO) Exploit — Empty-Market Exchange-Rate Inflation + Attacker-Controlled `oTokenRepay` Liquidation
Loss · ~$3.8M — 4,107,530 VUSD borrowed (3.81M VUSD net), 7,350,326 XCN, 5,148 DAI, 0.2299 WBTC,…
Onyx Protocol is a Compound-v2 fork. Two facts make it exploitable:
OTSea Staking Exploit — `claim()` Re-Arms Already-Withdrawn Deposits (Double-Withdraw Drain)
Loss · ~$26K — 43,944,445 OTSea tokens drained from the staking contract (99.999% of its holding…
OTSeaStaking lets a user manage many individual deposits (a Deposit[] per account). A deposit's rewardReferenceEpoch field doubles as both its reward-accounting anchor a…
Penpie Exploit — Fake-Market Reward Inflation via Attacker-Controlled `getRewardTokens()`
Loss · This PoC slice nets 1,367.72 agETH + 901.79 rswETH (~2,270 ETH, ≈ $5.6M @ ~$2.5k/ETH). Th…
Penpie is a Pendle "boosting" layer: users deposit their Pendle LP market tokens into Penpie's PendleStaking contract, Penpie stakes them in Pendle for boosted yield, an…
PESTO (Pesto The Baby King Penguin) Exploit — Flash-Loan-Driven Tax Auto-Swap Self-Sandwich
Loss · ~0.5039 ETH profit to the attacker (~$1.3–1.4K at Sept-2024 prices)
PestoTheBabyKingPenguin is a "tax token". Wallet-to-wallet transfers are taxed 70% (_transferTax), and the tax accumulates inside the token contract itself. On any sell…
Planet Finance (PLN) Exploit — Zero-Amount Transfer Triggers Uncompensated Pool Burn
Loss · ~$400k — 164.99 WETH net drained from the WETH/PLN Uniswap-V2 pair (attacker received 165…
PLNTOKEN is a "deflationary" meme token (Planet Finance). Inside its _transfer it has a special branch: when a fee-exempt address sends tokens to the dead address it cal…
Pythia Staking Exploit — Reward-Debt Reset via Receipt-Token Transfer
Loss · ~21 ETH (per PoC header). In the reproduced fork, the attacker turned a 0.5 ETH stake (≈3…
PythiaTokenStaking is ERC20 + AbstractRewards. When you stake(amount) it mints you amount of the staking receipt token SPythia and books a "reward debt" (pointsCorrectio…
Shezmu Exploit — Unprotected `mint()` on the Vault Collateral Token
Loss · ~$4.9M realized (attacker minted 98,999,168,398 ShezUSD of fake stablecoin, then sold wha…
Shezmu is an over-collateralized CDP/stablecoin protocol: deposit a whitelisted collateral token into a ERC20Vault, and the vault lets you borrow() up to ~70% of the col…
SmartSession enable-mode can be frontrun to install signed policies under a different permissionId
Sniper-Bot Exploit — Unprotected Arbitrary-Call Function Drains a Standing WETH Allowance
Loss · ~$12K — 5.049899842444876795 WETH drained from the victim
The victim (0x7c243E…, an EOA whitelisted by the bot) had granted the bot a near-infinite WETH approval (99,999,999,999.998 WETH) so the bot could trade WETH on their be…
Unverified `0x03F9…` Exploit — Permissionless Uniswap V3 Swap-Callback WETH Drain
Loss · ~$1.7k — 0.737035470365687848 WETH (the victim contract's entire WETH balance)
The victim contract 0x03F911…62c0 is a small (≈2.9 KB) helper that holds WETH and exposes an external uniswapV3SwapCallback(int256,int256,bytes) (selector 0xfa461e33). A…
Unverified `0xb309…28Cb` MEV Router — Unprotected `uniswapV3SwapCallback` Token Drain
Loss · 0.36 WETH drained in this tx (≈ $0.9k at Sept-2024 prices; the campaign across the two kn…
0xb309…28Cb is a MEV / arbitrage router that performs Uniswap-V3 flash swaps. A V3 swap works by optimistically sending the output to the recipient and then swap() invok…
WXETA (Wrapped Xeta) Exploit — Unprotected Diamond-Facet `initialize()` → Unlimited Mint → AMM Pool Drain
Loss · ~49,847.5 BUSD drained from the WXETA/BUSD PancakeSwap pair, swapped to 88.30 WBNB (≈ $11…
WXetaDiamond is an EIP-2535 "Diamond" proxy whose token logic lives in a single WXETA facet. That facet keeps its own state in an independent diamond-storage namespace (…
0x8DE7…34E9 Exploit — Permissionless `grantRole` Lets Anyone Self-Grant Admin and Drain the Bridge/Custody Handler
Loss · 10,463.638549999999999999 DAI (≈ $10.5k) drained from the custody/handler contract
The vulnerable contract 0x8DE7…34E9 is an OpenZeppelin-AccessControl-based admin router. Its privileged adminWithdraw(...) function is correctly protected — calling it w…
AAVE ParaSwap Repay Adapter — Lingering Allowance + Arbitrary-Call Collateral Drain
UntaggedLoss · ~$56,000 across all tokens left in the adapter. PoC steals only the wstETH leg: 0.4259665…
ParaSwapRepayAdapter is a helper contract that lets an Aave user "repay debt with collateral": it pulls the user's aTokens, withdraws the underlying collateral, sells it…
COCO COIN Incident — Abused USDT Allowance Drained via the COCO/USDT Pool
Loss · 280 BNB total across the campaign (per the PoC header / TenArmor). The reproduced slice m…
Despite the way the PoC is framed (and the empty "Vulnerable Contract" field in its header), there is no exploitable code defect in either the COCO token or the PancakeS…
Convergence Finance Exploit — Unvalidated `claimContracts` Lets a Fake Staking Contract Mint the Entire Staking Allocation
Loss · ~$200,000 — 58,718,395.06 CVG minted out of thin air (the entire unminted staking allocat…
The Convergence reward path CvxRewardDistributor.claimMultipleStaking() accepts a claimContracts array directly from the caller and, for each element, calls claimContrac…
iVestDAO Exploit — `skim()` Re-Routed Through a Reflection Token's Burn-Donation Hook
Loss · ~338.28 WBNB (~$190K at the time) — net profit drained from the iVest/WBNB pair
iVESTDAO is an RFI-style reflection token (4 decimals, 1e9 max supply) with a "donations & karma" layer bolted on top. Inside its _transfer (iVESTDAO.sol:1445-1532):
NovaX M2E Exploit — Stake/Withdraw USD-Value Sandwich via Manipulable AMM Oracle
Loss · ~$25,223 — net 25,223.19 USDT extracted in a single transaction
TokenStake lets users stake the NovaX (M2E) token and later withdraw the same dollar value they staked. The catch is how "dollar value" is measured. At stake time the co…
OMPxContract Exploit — Purchase/BuyBack Price Asymmetry Round-Trip Drain
Loss · 4.372869914943298 ETH (~$11,527 at the time) — the entire ETH reserve of OMPxContract
OMPxContract lets users purchase() OMPX with ETH and buyBack() OMPX for ETH. Both sides price OMPX off the same formula — getBuyBackPrice = (contractEthBalance − feeBala…
Pepper — minting limit uses `totalSupply`, blocking legitimate minter airdrops
1. mint (MINTER_ROLE) caps against global totalSupply, intended as a 40% airdrop budget. 2. claim also increases totalSupply outside that role. 3. After claims alone hit…
Phi — `shareBalance` bloating eventually blocks curator rewards distribution
1. Cred tracks each cred's curator share balances in an EnumerableMap (shareBalance[credId]). Buying adds/increases an entry; selling decreases it. 2. When a curator ful…
Phi — Exposed public _add/_removeCredIdPerAddress bricks victim sells
Public _removeCredIdPerAddress lets anyone strip a victim's credId list so their subsequent sell reverts and shares are frozen
Phi — Forced endTime extension in updateArtSettings allows attacker to mint
After a mint event ends, updateArtSettings forces endTime_ >= now, reopening minting so an attacker can snipe residual maxSupply and dilute holders
Phi — reentrancy bypasses the cooldown, enabling flash-loan-style reward extraction
1. Cred.buyShareCred refunds any excess ETH payment via a raw call to msg.sender — and only after that call returns does it arm lastTradeTimestamp, the state a 10-minute…
Phi — Reentrancy in creating Creds allows an attacker to steal all Ether from the Cred contract
1. createCred writes creds[credIdCounter], then buyShareCred (auto-buy 1 share). 2. buyShareCred refunds excess ETH via an external call before credIdCounter is incremen…
Phi — signature replay in `createArt` allows impersonating the artist
1. PhiFactory.createArt(signedData_, signature_, config_) verifies a signature over (expiresIn_, uri_, credHash_) only — the CreateConfig (artist/receiver/royaltyBPS) is…
Phi — signature replay in `signatureClaim` ignores chain id
1. PhiFactory.signatureClaim unpacks its signed encodeData_ into (expiresIn_, minter_, ref_, verifier_, artId_, , data_) — the sixth tuple slot is bound to nothing; it i…
Royco ERC4626i — Missing permissions check in withdraw and redeem
1. ERC-4626 redeem(shares, receiver, owner) must require msg.sender == owner or sufficient allowance. 2. Royco's ERC4626i omits that check entirely. 3. An attacker calls…
Royco ERC4626i — User rewards can be permissionlessly erased
1. updateUserRewards(campaignId, user) is public and callable for any user. 2. It overwrites userData.accumulated = (balance elapsed rate) / WAD instead of accruing. 3.…
Royco RecipeOrderbook — successful transfers on non-existent tokens let attackers steal reward tokens
1. Solmate's SafeTransferLib does not check that a token has code. A CALL to a codeless address returns success with empty returndata, and the library's iszero(returndat…
Tadle — `DeliveryPlace::settleAskTaker()` mistakenly uses `makerInfo.tokenAddress`
1. When a buyer settles an ask taker position, settleAskTaker correctly pulls in the settlement amount using marketPlaceInfo.tokenAddress — the actual point token config…
Tadle — `DeliveryPlace::settleAskTaker` has incorrect access control
1. settleAskTaker's own devdoc says the caller must be the stock authority — the party who actually holds the Ask-type settlement stock and is obligated to deliver point…
Tadle — formulaic error rounds down, causing total loss of funds for bid takers during abort
1. abortBidTaker refunds a taker's deposit after their bid offer is aborted, using depositAmount = stockInfo.points.mulDiv(preOfferInfo.points, preOfferInfo.amount, Floo…
VOW / Vow Finance Exploit — Permissionless 100× VOW→vUSD `tokensReceived` Mint Mispricing
Loss · ~$1.0M — 175.48 ETH + 595,970.52 USDT + 5,801,632.71 VOW extracted, draining the VOW/WETH…
VSCTokenManager implements the VOW→vUSD conversion: send VOW to it (via the ERC777 tokensReceived hook), it burns the VOW and mints you vUSD ("VSC", a $1-pegged stableco…
Yodl Router Exploit — Permissionless `transferFee()` Drains Pre-Approved User Allowances
Loss · 47,809.355551 USDC (~$47.8K; the PoC header rounds to "~5k", but the on-chain drain repro…
YodlRouter exposes a public, unauthenticated helper transferFee(amount, feeBps, token, from, to) (src_AbstractYodlRouter.sol:162-187). Every single parameter is attacker…
Zenterest Exploit — Stale-Oracle Collateral Mispricing on a Compound Fork
Loss · ~$21,000 — the attacker drained zenWHITE's available cash by borrowing 89.91 WHITE agains…
ZenterestPriceFeed is a push-style oracle: an off-chain reporter periodically signs/submits prices via updatePrice / updateDelegatedPrice, each carrying an updatedAt tim…
ArkProject NFT Bridge — The bridging process will revert if the collection is matched on the destination chain and not on the source chain
1. L1Bridge.withdrawTokens() calls _verifyRequestAddresses() to confirm the withdrawal request's L1 and L2 collection addresses match the bridge's own recorded pairing b…
Basin — `WellUpgradeable` can be upgraded by anyone
1. WellUpgradeable is Basin's upgradeable Well variant: UUPSUpgradeable + OwnableUpgradeable, deployed behind an ERC-1967 proxy. 2. OpenZeppelin's docs are explicit: the…
Basin — Incorrectly assigned `decimal1` in `decodeWellData`
UntaggedWhen well data encodes decimal1 = 0 (meaning “default to 18”), the decoder checks decimal0 == 0 instead of decimal1 == 0, so decimal1 stays 0. Scaling token1 reserves by…
Common Pool — signature omits nonce/expiry and can be reused
1. Signed digest is keccak256(abi.encode(DEPOSIT_STRUCT, multicall/amount)) only. 2. sig.nonce and sig.expiry are checked but not bound into the digest. 3. Observer re-s…
DeFiPlaza Exploit — Constant-Product `swap` Degenerates When the Input Reserve Is Drained to Zero
Loss · ~$200K — the entire honest liquidity of the DeFiPlaza 16-token pool drained as a basket (…
DeFiPlaza is a single-contract, 16-token DEX where every trade follows a pairwise x·y=k curve priced directly off IERC20(token).balanceOf(address(this)). The swap math i…
DoughFina Exploit — Permissionless Flash-Loan Connector Drains Any User's DSA
Loss · ~$1.81M (multiple victim DSAs drained; this PoC reproduces one DSA → 596.74 WETH ≈ $1.78M…
DoughFina users each get their own DSA (DeFi Smart Account, a DoughDsa proxy) that holds their Aave V3 position. A "deleverage" connector (ConnectorDeleverageParaswap, C…
GAX Swap Exploit — Caller-Dictated Output Amount With No Input/Price Check
Loss · ~$49,583.84 — the contract's entire 49,583.844 USDT (BEP20 0x55d3…7955) balance
The vulnerable contract is a simple "sell GAX, receive USDT" desk. Its swap entry point (selector 0x6c99d7c8) takes three raw uint256 arguments — effectively swap(uint25…
Gorples — missing `xBorpaBalances` decrement in `finalizeRedeemFor`
1. finalizeRedeem correctly does xBorpaBalances[msg.sender] -= xAmount then pays Gorples. 2. finalizeRedeemFor pays via _easyFinalizeRedeem but never decrements xBorpaBa…
Karak — [H-02] An operator can create a `NativeVault` that is silently unslashable
1. In Karak, an operator deploys a NativeVault via Core.deployVaults(), passing extraData = (manager, slashStore, nodeImplementation). 2. NativeVault.initialize() stores…
Karak — [H-03] A DoS on snapshots due to a rounding error in calculations
1. NativeVault.startSnapshot() calls _transferToSlashStore(), which computes slashedAssets = node.totalRestakedETH - convertToAssets(balanceOf(nodeOwner)). 2. NativeVaul…
Karak — [H-04] Violation of Invariant Allowing DSSs to Slash Unregistered Operators
1. An operator can request to unstake their vaults from a DSS, starting a 9-day MIN_STAKE_UPDATE_DELAY. 2. While that request is still pending, the DSS can legitimately…
LI.FI Protocol Exploit — Arbitrary External Call via Unvalidated `depositToGasZipERC20`
Loss · ~$10M across many approved wallets / multiple tokens
LI.FI's GasZipFacet.depositToGasZipERC20() is a public, unguarded function that forwards a fully attacker-controlled LibSwap.SwapData straight into LibSwap.swap() (GasZi…
LinkingTheWorld (LW) Exploit — `_internalSwap` Underflow Mints Infinite Self-Balance & Drains the Fee Pool
Loss · ~7,395.94 BUSDT (≈ $7.4K) drained from the LW/BUSDT PancakeSwap pool
DexToken is a fee-on-transfer ("tax") token. On every taxed sell it converts part of the seller's tokens into the pool's quote asset (BUSDT) by calling pair.swap() direc…
MEV Bot `0xDd7c…3685` Exploit — Forgeable Uniswap-V3 Callback Authentication
Loss · ~$19K — 3.481 WETH + 4,021.32 USDT + 3,023.95 USDC drained from another MEV bot (ETH ≈ $3…
The vulnerable contract is a Uniswap-V3-style MEV / arbitrage bot. Like every V3 integrator, its uniswapV3SwapCallback(int256, int256, bytes) (selector 0xfa461e33) must…
Minterest (Mantle) Exploit — Stale Exchange-Rate in `lendRUSDY` Inflates mUSDY Collateral
Loss · ~427 ETH — 223 WETH + 204 mETH (~$1.36M at the fork-block WETH price of $3,193) drained f…
Minterest deployed a special market, mUSDY, that lets users supply collateral denominated in Ondo's rebasing rUSDY token while the market accounts internally in the unde…
MRP / WMRP Exploit — ERC314 Add/Remove-Liquidity Reserve Drain via Re-entrant Self-Buy
Loss · ~17.96 BNB drained from the WMRP internal AMM pool (≈ the pool's entire ~18.28 BNB tradea…
WMRP is an ERC-314-style "self-contained AMM" token: instead of using an external pair, the token contract itself holds BNB and WMRP and prices swaps off its own balance…
NLX — non-refunded excess fee in `_setPricesFromPriceFeeds`
1. _setPricesFromPriceFeeds reads updateFee = pyth.getUpdateFee(...) and requires msg.value >= updateFee. 2. It calls pyth.updatePriceFeeds{value: updateFee}(...) — only…
SmartBank (SBT) Exploit — Self-Referential Spot-Price Oracle Manipulation
Loss · ~56,470 BUSD (the SmartBank's entire USDT/BUSD reserve)
Smart_Bank runs a tiny in-house "DeFi bank": you can buy/sell its SBT token and take USDT loans against SBT collateral. Every price it uses is computed live from its own…
Spectra Finance Exploit — Arbitrary External Call via the Router's `KYBER_SWAP` Command
Loss · ~$73,000 — 188,013.365 asdCRV drained from a single victim's wallet
Spectra's Router is a Uniswap-Universal-Router-style command dispatcher: callers pass a byte string of commands and a matching array of ABI-encoded inputs to execute(...…
TempleGold — incompatibility with multisig wallets in `send()`
1. TempleGold.send(_sendParam, _fee, _refundAddress) is the entry point users call to bridge TEMPLE from one chain to another via LayerZero. 2. Before doing anything els…
TraitForge — Buyer burn/nuke slashes original minter's airdrop allocation
UntaggedBuyer burn/nuke slashes original minter's airdrop allocation. Harm demonstrated: Seller airdrop allocation slashed to zero by buyer burn after transfer.
TraitForge — incorrect percentage calculation in NukeFund and EntityForging
1. taxCut is meant to be a percentage — the code's own comment calls the default value of 10 "the developer's share (10%)". 2. Both NukeFund.receive() and EntityForging.…
TraitForge — the maximum number of generations is infinite
1. TraitForgeNft is meant to cap total supply at maxGeneration generations of maxTokensPerGen NFTs each (real protocol: 10 x 10,000 = 100,000). 2. Filling a generation's…
TraitForge generation count reset lets forged entities bypass the cap
Loss · The per-generation entity cap is bypassed; forged entities are omitted from the next gene…
forge() can create an entity assigned to the next generation and increment that generation's counter before the generation is active. When the current generation reaches…
TraitForge generation rollover is permanently blocked by the wrong modifier
Loss · Generation rollover reverts, bricking mintToken, mintWithBudget, and forge at the boundar…
TraitForgeNft is configured as EntropyGenerator.allowedCaller, but the audited function uses onlyOwner. On every generation rollover the NFT calls initializeAlphaIndices…
Unverified MEV/Arb Contract `0x452E25…` — Unauthenticated `uniswapV3SwapCallback` Drains Its Own WETH
Loss · 27.349 WETH (~$90.3K @ ≈ $3,300/ETH on the day) drained from the contract's own balance
The vulnerable address is an unverified contract — almost certainly a private MEV/arbitrage helper that performs Uniswap V3 swaps and therefore implements the Uniswap V3…
Zaros — draining the protocol fully
1. Opening a new order moves the market's skew, which moves the mark price (price impact) — a real feature (skew-based pricing). 2. The margin check for that SAME new or…
Zaros — incorrect logic for checking isFillPriceValid
1. Offchain (take-profit / stop-loss) orders are gated by isFillPriceValid, which should let a buy order fill once fillPrice = targetPrice (don't undersell / lock in the…
Zaros — LiquidationBranch::checkLiquidatableAccounts() array out-of-bounds
1. checkLiquidatableAccounts(lowerBound, upperBound) is explicitly designed for segmented/paginated scanning of active trading accounts (per its own NatSpec @param docs)…
Zaros — SettlementBranch._fillOrder does not guarantee collateral covers the future liquidation fee
1. Opening a position (_fillOrder) deducts the settlement fee and order fee from the trader's margin balance. 2. It never checks that whatever margin remains afterward c…
Zaros — wrong parameter passed in TradingAccount::deductAccountMargin
1. On liquidation, deductAccountMargin should realize the account's ACTUAL unrealized loss plus the liquidation fee out of its margin balance, transferring that amount t…
APEMAGA Exploit — Public `family()` Backdoor Burns 99.9% of the Pool's Token Reserve
Loss · ~9.25 WETH (~$34k at the time) — the entire WETH side of the APEMAGA/WETH pool
APEMAGA (verified contract name Tonken) ships a public, unauthenticated function family(address) that forwards to an internal _approve_. Despite the innocuous name, _app…
Astrolab — Accounts not properly removed from roles upon revoking
1. Roles are stored in AsSequentialSet.Set (data[] + 1-based index map). 2. remove(o) reads index[o] and calls removeAt, but never sets index[o] = 0. 3. has(o) returns t…
Bazaar (Ryolo LBP) Exploit — Missing `exitPool` Authorization Burns a Victim's Pool Shares to the Attacker
Loss · ~$1.4M total. PoC asserts the WETH leg: 392.368916743742801361 WETH drained, plus 880,539…
BazaarVault is a minimal re-implementation of the Balancer V2 IVault interface that backs the project's LBP (Liquidity Bootstrapping Pool) tokens. Its exitPool(poolId, s…
CRB2 Token Exploit — Fee-on-Transfer Reflection Drain via Self-`sellToken` Loop
Loss · ≈ 15,125.83 USDT (~$15.1K) extracted to the attacker EOA
CRB2 is a heavily-modified fee-on-transfer ("reflection") token. Two design choices combine into a free-money bug:
Dyson.money Exploit — Permissionless `harvest()` Sandwich Steals Pending Yield from a Near-Empty Vault
Loss · ~52 BNB — attacker turned 910 USDT + 910 USDC (≈ $1,820) into 15,003 USDT + 18,001.8 USDC…
DysonVault is a Beefy-style auto-compounding yield vault. It mints share tokens against balance() — the amount of want LP held by the vault's strategy — and lets anyone…
INcufi (AkitaDefender) Exploit — Self-Referral Commission Farming + Un-collateralized 1:1 `swapCommision`
Loss · ~$59,643 — 59,643.218325 BUSD (the staking contract's entire BUSD balance, drained to the…
INcufi is a referral-staking program. You stake BUSD; the contract pays your upline (sponsor / 2nd-level sponsor / country head) commissions denominated in a separate to…
JokInTheBox Staking Exploit — Missing `unstaked` Guard ⇒ Infinite Re-Unstake Drain
Loss · ~9.28 ETH of profit to the attacker (≈ $33–34k at the time); the JOK/WETH Uniswap-V2 pool…
JokInTheBoxStaking.unstake(stakeIndex) is supposed to return a stake's tokens exactly once. It sets a per-stake unstaked = true flag (JokInTheBoxStaking (1).sol:424.sol#…
MineSTM Exploit — `sell()` Redeems the Protocol's Own LP at an Attacker-Manipulated Price
Loss · ~$13.8K — 13,852.73 BUSDT of MineSTM-owned pool liquidity
MineSTM is a referral-tree "mining" / staking contract that accumulates a large LP position in the BUSDT/STM PancakeSwap-V2 pair (it auto-adds liquidity every time a use…
NCD Exploit — Uncapped Self-Mint Staking Reward Farmed Across Disposable Contracts
Loss · ~$6,496 — 6,496.24 USDT (BSC-USD) drained from the NCD/USDT PancakeSwap pair
The NCD token has a built-in "mining" reward: any address whose mineStartTime[addr] is set accrues 1.5% of its own balance per day, and that reward is freshly minted to…
Notional Leveraged Vaults (Kelp) — a dust withdrawal request permanently freezes the real one
1. KelpCooldownHolder._finalizeCooldown() always looks at index 0 of LidoWithdraw.getWithdrawalRequests(address(this)) to decide what's finalized and what to claim. 2. L…
Serious — locking other tokens' collected ETH by triggering `createPoolAndAddLiquidity` twice
1. Every token's buyers pay ETH into the SAME SeriousMarketProtocol contract balance while their token is being funded. 2. Once a token is fully funded, anyone can call…
Serious — Uniswap's pool can be initialized with a different price
1. createPoolAndAddLiquidity creates AND initializes the Uniswap V3 pool only if it doesn't already exist. 2. Anyone can create and initialize a Uniswap V3 pool for any…
SteamSwap (MineSTM) Exploit — `sell()` Redeems the Protocol's Own LP To Any Caller
Loss · ~$91.5k — 91,514.91 BUSD (USDT, 0x55d3…) net profit drained from MineSTM's pool position
MineSTM is the staking/mining core of "SteamSwap". Users deposit USDT via lpMint(); the contract converts that USDT into BUSD/STM liquidity and holds the resulting LP to…
UwuLend (2nd hack) — Hardcoded `$1.04` sUSDE Oracle + Live 80% Liquidation Threshold
Loss · ~$3.73M — drained across 7 reserves (350.19 WETH + crvUSD + DAI + USDT + FRAX + LUSD + CR…
This is the second UwuLend exploit, ~13 days after the first one ($19.3M, sUSDE Curve-EMA oracle manipulation). After the first hack, UwuLend tried to "patch" sUSDE pric…
UwuLend Exploit (#1) — sUSDe Oracle Manipulation via Curve Spot Prices in the Median
Loss · ~$19.3M total drained from UwuLend (this PoC nets 811.50 WETH, the WETH-denominated resid…
UwuLend prices sUSDe through a custom feed, sUSDePriceProviderBUniCatch.getPrice(). That feed collects 11 candidate prices of USDe-in-USD across five Curve pools plus on…
Velocore V2 Exploit — `feeMultiplier` Overflow Turns a Withdrawal Into a Pool Drain
Loss · $6.88M total across all Velocore pools. This PoC reproduces the drain of the USDC.e/ETH p…
Velocore's weighted/constant-product pool charges an escalating withdrawal fee to discourage sandwiching a single large exit across several smaller exits in the same blo…
Vultisig — adversary can prevent the launch of any ILO pool with enough raised capital, at any moment, by providing single-sided liquidity
1. ILOManager.launch() requires the ILO pool's CURRENT Uniswap V3 price to exactly equal the price cached when the project was initialized — otherwise it reverts with "U…
Vultisig — most users won't be able to claim their share of Uniswap fees
1. Multiple ILO investor NFT positions share ONE underlying Uniswap V3 position (same TICK_LOWER/TICK_UPPER), so they also share one pool of accrued swap fees. 2. claim(…
Vultisig — whitelist index zero lets every unlisted buyer purchase
The whitelist map returns zero for an account that has never been added. The validation only rejects an index above the configured maximum. With a maximum of 10, index z…
WIFCOIN (WIFStaking) Exploit — Time-Ungated `claimEarned()` Reward Loop Drains the Staking Pool
Loss · ~3.41 ETH profit to the attacker; the entire WIF balance of the staking contract (~1.137…
WIFStaking.claimEarned() pays out staking rewards computed as a fixed fraction of the staked principal (amount × apr / 10000) but never checks elapsed time and never enf…
WILL "Trading" Exploit — Over-Sized, Slippage-Free `settleExpiredPositions()` Buy-Back Sandwich
Loss · ~52,434 USDT (~$52,777) drained from the trading contract's USDT balance
trading is a leverage "short-selling" protocol on BSC. A user opens a short with placeSellOrder(usdtAmount, margin, minUsdtReceived): the contract pulls usdtAmount USDT,…
YYS / YYSCoin Exploit — `sell()` Returns the Tokens It "Sold" (Double-Payout Drain)
Loss · ~$28.9K — 28,937.96 BUSD-T net, drained from the YYS/BUSD-T PancakeSwap pair and the proj…
The YYS project runs a custom MLM/reward contract (the "invest" contract at 0xcC0F…, unverified) that offers a sell(uint256 amount) helper so users can liquidate their Y…
EXcommunity (EXboy / EXgirl) Exploit — `purchasedAmount` Inflation via Zero-Value `transferFrom` + Pool Donation
Loss · ~32.89 BNB (~$18–20K at the time) net profit to the attacker
EXgirl is a "smart rebalancing" ERC20 paired with BUSDT. Whenever tokens move from the pair (i.e. someone buys EXgirl), its _update hook tries to measure how much BUSDT…
Galaxy Fox (GFOX) Exploit — Permissionless `setMerkleRoot()` Lets Anyone Forge an Airdrop Claim
Loss · ~$330K — 1,335,339,824.39 GFOX drained from the airdrop distributor (75% of its entire 1.…
The GFOX airdrop distributor verifies claims against a Merkle root: claim(to, amount, proof) recomputes the leaf keccak256(to, amount), walks the supplied proof to a roo…
GPU Token Exploit — Self-Transfer Balance Doubling
Loss · ~$32K — attacker BUSD balance grew from 26.54 BUSD → 32,624.62 BUSD (≈ +32,598 BUSD net)
GPU is a fee-on-transfer "DeFi" token. Buried under its tax/auto-liquidity machinery, every plain transfer that is not to/from the AMM pair eventually calls the inherite…
Linea TokenBridge — ERC721 becomes permanently one-way
The ERC20 bridge accepts an ERC721 because both expose a transferFrom-shaped call. The NFT is locked and represented as one fungible unit, but the return flow cannot rel…
Liquidity Tokens (TLN / VOW / VUSD) Exploit — LP-Stake Reward Inflation & 1:1 TLN→vUSD Redemption
Loss · ~$200K — attacker netted 108,028.99 BUSD (USDT) + 1,463,194.51 VOW after repaying a 19M-U…
The protocol lets a user stake VOW/VUSD LP tokens into a staking pool (0x85F8…A5f8). The pool mints fresh TLN as a staking reward, and the reward size is computed from t…
MetaDragon (P404) Exploit — Permissionless NFT Burn Mints Free ERC20
Loss · ~$180K reported by the original disclosure (aggregate across the full attack). This singl…
MetaToken is an ERC-404-style dual asset: a small tokenId (≤ 30000) is treated as an ERC721, while a large value is treated as the fractional ERC20. Sending the "ERC721…
MixedSwapRouter Exploit — Arbitrary `transferFrom` via Fake "Pool" + Same-Token Path
Loss · ~293,182 WINR (≥ $10,000 USD per the PoC header) drained from a victim's wallet
MixedSwapRouter lets a caller supply the pool[] array for a swap, and treats any contract that exposes a non-reverting fee()/token0()/token1()/swap() ABI as a valid "V3…
Munchables — Invalid validation allows users to unlock early
1. When a user locks tokens, unlockTime = block.timestamp + lockDuration and lastLockTime = block.timestamp are recorded together, at the same instant. 2. setLockDuratio…
Munchables — Malicious user can call lockOnBehalf to repeatedly extend a user's unlockTime
1. LockManager.lockOnBehalf(tokenContract, quantity, onBehalfOf) lets any caller donate tokens "on behalf of" any other address — with no access control and no minimum q…
NORMIE Exploit — Phantom Self-Mint via the `premarket_user` Flag + `skim()` Recycling
Loss · ~$490K — the WETH/NORMIE pool's WETH reserve drained from 173.04 → 21.14 WETH (≈ 151.9 WE…
NORMIE is a meme token with an auto-liquidity / fee-distribution tax engine. Buried inside its _transfer is this branch (NORMIE.sol:906-912):
OSN Exploit — LP-Dividend Farming via Instant `setBalance`→`processAccount` Reward Payout
Loss · +1,757.97 USDT net to the attacker; ~12,163 USDT of sell-tax dividends siphoned into atta…
OSN is a "reflection / dividend" token: a 3.5% sell tax is swapped to USDT and distributed pro-rata to liquidity providers through a DividendTracker. A holder's dividend…
pNetwork `Burner` Exploit — Permissionless `convertAndBurn()` + Slippage-Free Kyber Trade → Sandwich
Loss · ~1.726 WETH (≈ $5–6K at the time) extracted from the Burner contract's fees + PNT/WETH po…
Burner is pNetwork's fee-burning helper: it accumulates protocol fees in various tokens (ETH, WBTC, USDT, …), and its convertAndBurn(tokens[]) swaps each of those into t…
Predy Finance Exploit — Permissionless Pair Registration + Lock-Settlement Bypass Drains the Shared Pool
Loss · ~$464K — 83.91 WETH + 219,585.74 USDC drained from the shared PredyPool
PredyPool is a single monolithic contract that custodies all assets for all trading pairs. Two design flaws compose into a free, single-transaction drain of the entire p…
RedKeys Game Exploit — Predictable On-Chain "Randomness" Lets the Player Always Win
Loss · ~$12K — house bankroll of the RedKeysGame contract drained in REDKEYS
RedKeysGame is an on-chain coin-flip casino. You call playGame(choice, ratio, amount), stake some REDKEYS, and if your choice matches the game's "random" _betResult you…
SATURN Token Exploit — `AutoNukeLP` Burns the Pool's Reserve on Every Sell
Loss · ~15 BNB — net 14.17 WBNB drained from the SATURN/WBNB PancakeSwap pair
Saturn is a "deflationary" token that, on any transfer into its own liquidity pair, burns SATURN tokens directly out of the pair's balance and then calls pair.sync() (co…
SCROLL Token Exploit — Uniswap `UniversalRouter` Drained via a `balanceOf == type(uint256).max` Trap Token
Loss · 76.36 WETH (≈ 76 ETH, ~$290K at the May-2024 ETH price) drained out of the SCROLL/WETH Un…
The Uniswap UniversalRouter is a stateless multicall router: it is intended to hold no funds between transactions, and its execute(commands, inputs) entry point is permi…
Sonne Finance Exploit — Empty-Market Exchange-Rate Inflation (CompoundV2 Donation Attack)
Loss · ~$724,290 USDC in this reproduced transaction; ~$20M total across the Sonne campaign on O…
Sonne Finance is a CompoundV2 fork. Each lending market (CErc20) prices its cToken against the underlying with the classic formula exchangeRate = (cash + totalBorrows -…
TCH Exploit — Signature-Replay Loophole + Pool-Reserve `_burn`/`sync()` Price Manipulation
Loss · ~$18,589 — 18,589.29 BUSDT skimmed from the BUSDT/TCH PancakeSwap pair
TCHtoken.burnToken() lets anyone present an off-chain ECDSA signature from an authorizedSigner to trigger a "deflation": it removes 0.4% of the pool's TCH balance and ca…
TGC Exploit — Broken Pledge-Reward Math Mints 113,000× the Stake
Loss · ~$29.6K (PoC, this block) / ~$32K reported — ≈29,729 USDT drained from the TGC/USDT Panca…
The TGC "pledge" contract lets a user stake TGC (joinPledge(amount), selector 0x836aefb0) and later claim accrued rewards (claim(), selector 0xfd5a466f). The reward form…
Trade On Orion (Orion Protocol BSC) Exploit — `redeemAtomic` Missing Position Check + Liability-Free `requestReleaseStake`
Loss · ~$645K — drained from the Orion Exchange vault as 498,921.92 ORN + 79.90 BNB + 62,444.73…
Orion's Exchange keeps an internal ledger of user balances as signed integers (mapping(address => mapping(address => int192)) assetBalances). A negative balance is allow…
TSURU Wrapper Exploit — Unprotected `onERC1155Received` Free-Mint Drains the LP
Loss · ~$140K — 137.904209005799603676 WETH drained from the TSURU/WETH Uniswap V3 pool
TSURUWrapper is an ERC-20 "wrapper" that is supposed to mint TSURU only when someone actually transfers in a backing ERC-1155 (or ERC-721) NFT. The minting logic lives e…
ATM Token Exploit — Forced Zero-Slippage Auto-Swaps Drained via `transfer` + `skim`
ATM is a "tax token" that, on every sell, takes a 3% fee in ATM into its own balance and then runs distributeCurrency() (Token.sol:1102). That routine sells the contract…
BigBangSwap Exploit — `sellRewardToken` Pays Out Against a Richer Pool Than the Seller Bought From
Loss · ~5,085 BUSD extracted from the protocol (≈ $5,085); attacker net profit ≈ 3,984.6 BUSD af…
BigBangSwap lets BGG holders "sell" their BGG to the protocol via sellRewardToken(amount) on the proxy 0xa45D43…. Internally the function:
BNBX Exploit — Unprotected Public `transferFrom` Drains Every Approver
Loss · ~5 BNB (~$2.8K at the time) — BNBX siphoned from every wallet that had approved the helpe…
Helper contract 0x389A…1C24 exposes a public, unauthenticated function (selector 0x11834d4c, one address argument) whose entire body is:
Chainge Finance Exploit — Arbitrary External Call in `MinterProxyV2.swap()` Drains Approvals
Loss · ~$200K across 12 tokens (USDT, SOL, AVAX, BabyDoge, FLOKI, ATOM, TLOS, IOTX, 1INCH, LINK,…
MinterProxyV2 is the cross-chain bridge "minter/vault" contract for Chainge Finance. Its swap() function is meant to take a user's input token, route it through an aggre…
DYAD — Flash loan protection mechanism can be bypassed via self-liquidations
1. VaultManagerV2 records idToBlockOfLastDeposit[id] = block.number on every deposit(), and withdraw() reverts if that marker equals the current block — blocking a same-…
DYAD — Initialization of DyadXPv2 is impossible (unbounded init loop DoS)
1. DyadXPv2 is an upgradeable contract. On upgrade, initialize() runs once and must fit inside a single block. 2. initialize() eagerly loops over every DNFT (for i in 0.…
FIL314 Exploit — Permissionless `hourBurn()` Crushes the Self-Contained AMM Reserve
Loss · ~14.08 BNB drained from FIL314's built-in BNB reserve (header reports "~14 BNB")
FIL314 is an ERC314-style token: instead of pairing with PancakeSwap, it embeds its own single-sided AMM inside the token contract. The "reserves" are two contract field…
GFA (Generation Finance Academy) Exploit — Permissionless `setReward` / `generateReward` Self-Mint
Loss · ~$14,697 — net 14,697.5 BUSD drained from the GFA/BUSD PancakeSwap pair
The GFA token has a "pawn-to-mine" reward system. Real users lock ("pawn") GFA via _toPawn, and the token's internal Reward bookkeeper records a future payout for them (…
Gondi — distribute() lacks access control (Pool accounting corruption)
Untagged1. distribute() is permissionless. 2. Attacker crafts a loan: principalAddress = Junk, sole lender = Pool. 3. Junk is transferred to the Pool; loanLiquidation does total…
Gondi — front-running repayLoan via loanId rotation
Untagged1. repayLoan requires _loan.hash() == _loans[loanId]. 2. mergeTranches writes a new loanId and delete _loans[old]. 3. Front-running a repay with merge makes the old id i…
Gondi — incorrect `_pendingWithdrawal` accounting in queueClaiming
Untagged1. queueClaimAll walks each queue's getTotalReceived and distributes into newer queues. 2. Distribution writes _pendingWithdrawal[secondIdx] = pendingForQueue. 3. A seco…
Gondi — refinanceFromLoanExecutionData missing tokenId check
Untagged1. Refinance re-uses the NFT already in escrow (no transfer out/in). 2. Offer validation uses attacker-controlled executionData.tokenId. 3. No check that it matches the…
Gondi — settleWithBuyout skips LoanManager.loanLiquidation
Untagged1. Gondi Pool implements LoanManager.loanLiquidation to clear outstanding and credit cash/queues. 2. settleWithBuyout transfers owed principal to other lenders (includin…
Gondi — triggerFee stolen from other auctions in settleWithBuyout
Untagged1. Multiple auctions share one contract balance of the principal asset. 2. Buyout correctly pulls other-lender repayment from the buyer. 3. triggerFee is paid with safeT…
GROKD Exploit — Permissionless `updatePool()` + `depositFromIDO()` Reward Pool Drain
Loss · ~129.8 BNB in this fork reproduction (~$72.7K at ~$560/BNB, Apr 2024); the live attack ac…
The GROKD project ran a MasterChef-style staking / IDO contract behind an ERC-1967 proxy. It is the GROKD token's LiquiditySharePool — the contract that receives the tok…
Hackathon Token Exploit — `sender == recipient == pair` Double-Credit Balance Inflation via `skim()`
Loss · ~$20,911 — 20,910.97 BUSD net profit (drained from the Hackathon/BUSD pair's BUSD reserve)
The Hackathon BEP20 token has a fee-on-transfer _transfer that splits behaviour into a BUY branch and a SELL branch — but it uses two independent if statements instead o…
Hedgey Finance Exploit — Dangling Approval to Attacker-Controlled `tokenLocker`
Loss · 1,303,910.12 USDC drained from the ClaimCampaigns contract in a single tx. Total Hedgey i…
ClaimCampaigns is a shared, multi-tenant escrow: many token projects deposit tokens into the same contract to fund their airdrop "claim campaigns." For locked/vesting ca…
Hoppy The Frog Exploit — Tax-Token Auto-Swap Reserve Manipulation
Loss · ~0.38 WETH profit to the attacker (PoC: 0 → 0.378824808020857200 WETH); the victim pool a…
Hoppy is a copy-paste "OpenZeppelin-style" meme tax token. On every taxed transfer it skims a fee into its own balance, and whenever a sell into the pair arrives while t…
MARS Exploit — Flash-Loan Reflection/Reserve Desync on a Fee-on-Transfer Pair
Loss · > $100K — the PoC nets ~14 WBNB of risk-free profit on a 350 WBNB flash loan, repeating a…
MARS is a reflection / fee-on-transfer token: every _transfer skims a tax and redistributes it as extra MARS balance to existing holders, including the liquidity pair. A…
NGFS (FENGSHOU) Exploit — Permissionless Privilege-Escalation Chain → Unlimited Mint
Loss · ~$95,902 reproduced in this PoC (one USDT-pool drain); ~$190K total across the USDT + WBN…
NGFSToken ships three "uniswap proxy" helper functions whose access checks form a bootstrap chain that any unprivileged caller can walk:
OpenLeverage (OPBorrowing) Exploit — Self-Liquidation Bad-Debt Drain via 1inch-Callback Price Manipulation
Loss · ~234,000 USD (per PoC header) — drained from the OpenLeverage OPBorrowing market #24 (WBN…
OpenLeverage's OpenLevV1.marginTrade() lets a caller supply arbitrary dexData that is executed by the DEX aggregator. When the dex id encodes the 1inch path (0x12aa3caf…
Pike Finance Exploit — Unguarded `initialize()` → UUPS Upgrade Hijack → ETH Drain
Loss · 479.39 ETH (≈ $1.58M at April 2024 prices). The PoC header's "$1.4M" total aggregates bot…
Pike Finance's custodial proxy is a UUPS-style upgradeable proxy whose initialize(owner, wNative, uniswapHelper, token, swapFee, withdrawFee) function lacked an effectiv…
Renzo — incorrect withdraw queue balance in TVL calculation
Untagged1. TVL loops ODs (i) then collateral tokens (j). 2. Withdraw-queue oracle call uses collateralTokens[i] for price but balanceOf token j. 3. With 1 OD and 3 tokens, token…
Rico / Ricobank Exploit — Arbitrary-Target `flash()` Drains the Bank's Reserves
Loss · ~$36K — every token the BankDiamond held was drained (10,375.58 USDC + 2,478.24 ARB + 69.…
Ricobank's flash-loan entry point, Vat.flash(address code, bytes calldata data) (src_vat.sol:286-300), does:
SATX Exploit — Permissionless `destroyPoolToken()` Reserve Manipulation + `skim()` Drain
Loss · ~49.34 WBNB (≈ $28K at the time) drained from the SATX/WBNB PancakeSwap pair
SATX is a tax/deflation token whose _transfer override calls destroyPoolToken() (SATX.sol:949-957) every time any holder transfers SATX to the liquidity pair (_isPairs[t…
SQUID Token Exploit — Permissionless 1:1 V1→V2 Migration + Public `sellSwappedTokens` Drain
Loss · ~$87K — 147.56 WBNB net profit extracted (10,000 WBNB flash-borrowed, repaid)
SquidTokenSwap is a "trustless" V1→V2 migration contract (contracts_SquidV1toSquidV2TokenSwap.sol). It offers two public functions:
Sumer Money Exploit — Reentrancy via `repayBorrowBehalf` Refund Inflates the ETH cToken Exchange Rate
Loss · ~$350K — 310,570.85 USDC + 10.877 cbETH (~$3,490 at ETH≈$3,377) taken from Sumer's markets
Sumer Money is a Compound-v2 fork on Base where the Ether cToken (CEther/sdrETH) reimplements repayBorrowBehalf. To refund overpayments it calls msg.sender.call{value: r…
Unverified Contract `0x00C409` Exploit — Manipulable AMM Callback Drains WETH Reserves
Loss · ~18.27 WETH (≈ $56K at late-April-2024 ETH prices)
The unverified contract at 0x00C409…003b exposes a Balancer-style swapExactAmountIn-like entrypoint (selector 0xba381f8f) but, instead of reading pool reserves and prici…
UPS (UtopiaSphere) Exploit — Sell-Side `_swapBurn` Drains the LP Pair via `skim`
Loss · ~$28,147 USDT drained from the UPS/USDT PancakeSwap V2 pair (the PoC comment reports ~$28…
UPS._update overrides ERC20 so that every sell into the pair (i.e. any transfer where to == pairAddress) silently calls _swapBurn(amount - fee), which does:
WSM Presale Exploit — Spot-Oracle Price Manipulation in `buyWithBNB()` via Flash-Loan Pool Crash
Loss · ~2,517,438 WSM (≈ $18K at the time) — tokens minted/transferred from the presale contract…
PresaleBSCV5.buyWithBNB() prices the WSM it sells with fetchPrice() (PresaleBSCV5Flat.sol:897-903), which calls Uniswap V3's Quoter.quoteExactOutputSingle() on the live…
XBridge Exploit — Permissionless `listToken()` Hijacks Token Ownership Then Drains Bridge Reserves
Loss · ~$1.6M total (ETH + STC + SRLTY + Mazi tokens held by the bridge)
XBridge is an upgradeable cross-chain bridge whose vault holds tokens that legitimate listers have deposited. The ownership of each token — i.e. who is allowed to call w…
YIEDL SpotVault Exploit — Zero-Share `redeem()` Token-Drain via Attacker-Controlled Swap Routing
Loss · ~127.48 BNB (≈ $77K at the time) drained from the YIEDL SpotVault portfolio
YIEDL's SpotVault.redeem() lets the caller pass an arbitrary bytes[] calldata dataList, then blindly forwards each entry to the trusted 1inch AggregationRouterV5 via fun…
Yield Protocol Strategy Exploit — Live-Balance `burn()` Donation Inflation
Loss · PoC realizes 95,158.56 USDC (~$95.2K) from a single 400K-USDC flash-loan cycle; the live…
Yield Protocol's Strategy vault (sources/Strategy_3b4FFD/.../Strategy.sol) issues ERC20 strategy shares against pool tokens (LP tokens of a YieldSpace pool). When a hold…
Z123 (SesameCloudToken) Exploit — Custom-Router `update()` Pool-Burn Arbitrage
Loss · ≈ 135,290 USD (BSC-USD, a.k.a. USDT) drained from the Z123/USD PancakeSwap V2-style pair
SesameCloudToken (ticker Z123) exposes an onlyMinter-gated update(address pair, uint256 amount) function (SesameCloudToken.sol:413-415) that does _transfer(pair, 0x…dEaD…
ALP (ApolloX) Exploit — Public `_swap()` Drains the Portfolio Vault's LP Tokens
Loss · ~$10,611 USDT (10,610.966044 USDT) — the vault's full ALP position, cashed out at market
StableCoinVault is an ERC4626-style "portfolio" vault that holds LP positions (here ApolloX ALP). Its internal helper _swap(tokenForSwap, aggregatorData) is the function…
Amphor — claim functions don't validate if the epoch is settled
1. When the vault is closed, users call requestDeposit() to queue an amount of assets against the current epoch (epochId). Nothing is convertible to shares until the own…
Amphor — exchange rate is calculated incorrectly when the vault is closed
1. AsyncSynthVault.deposit()/redeem() (the standard open-vault ERC4626 path) use the FAIR conversion rate: assets.mulDiv(totalSupply()+1, totalAssets()+1) — a single +1…
ARK Exploit — Public, Rate-Limit-Free `autoBurnLiquidityPairTokens()` AMM Reserve Drain
Loss · ~377.20 WBNB (~$130K at the time) drained from the ARK/WBNB PancakeSwap pair
ARK is an 18-decimal ERC-20 whose "auto-nuke LP" routine, autoBurnLiquidityPairTokens() (AbsToken.sol:776-786), is public and has no access control and no rate-limit che…
BBT Exploit — Permissionless `setRegistry()` + `mint()` Infinite-Mint Drain
Loss · 5.063858 ETH (~$17.2K at March 2024 ETH) drained from four Uniswap-V2 pools holding BBT/B…
BBToken (BBT) is an ERC-20 whose mint(address,uint256) is supposed to be callable only by authorized protocol modules — it checks that msg.sender == registry.getContract…
Binemon (BIN) Exploit — Permissionless `sweepTokenForMarketing()` Price-Manipulation Arbitrage
Loss · ~0.2 BNB (PoC-reproduced: +0.207952 WBNB). Real on-chain value extracted is small; the ve…
Binemon is a fee-on-transfer token that accrues a sell-fee pile of BIN inside its own contract (_transfer sends the 5% sell fee to address(this), Binemon.sol:1197-1208).…
Canto — native gas tokens stuck in `ASDRouter` on successful redemption
1. Successful lzCompose → _sendASD on same-chain delivery uses 0 of msg.value. 2. Error paths refund fully; success paths do not refund the remainder. 3. Protocol invari…
Curio Governance Token (CGT) Exploit — DAO Governance Takeover via Fake `DSChief` Vote + Timelocked `vat.suck` / `DSToken.mint`
Loss · Unauthorized mint of 1,000,000,000 CGT (≈ the entire intended supply) + 1,000,000,000 DAI…
Curio reused MakerDAO's governance primitives (DSChief voting + DSPause timelock) but backed DSChief voting weight with CGT, a token that had essentially no liquid marke…
DittoETH — attacker games a stale `updatedAt` to dispute a valid redemption and steal the penalty
1. disputeRedemption only trusts a disputer's Short Record as evidence that a redeemer's proposal wrongly skipped a lower-CR candidate if that Short Record's updatedAt i…
DittoETH — disputing a closed Short Record permanently locks its collateral
1. A redemption proposal removes debt (and marks pending) collateral from a Short Record, but does not lock that Short Record against ordinary closure. 2. The shorter ca…
DittoETH — flawed `&&` check corrupts protocol-wide collateral/debt accounting
1. claimRemainingCollateral(redeemer, claimIndex, id) lets a shorter reclaim a fully-redeemed Short Record's leftover collateral, but only after the NAMED redeemer's dis…
DittoETH — partially filled Short Records created without a short order cannot be liquidated or exited
1. When a short only partially matches the order book, sellMatchAlgo marks the Short Record's status PartiallyFilled — implying "the rest of this short is still resting…
EigenLayer — Beacon chain withdrawals at lastWithdrawalTimestamp are lost
Untagged1. activateRestaking sets mostRecentWithdrawalTimestamp = block.timestamp and sweeps pod ETH. 2. Beacon-chain withdrawals for that timestamp execute after user txs (EIP-…
ETHFIN Exploit — Permissionless `doBuyback()` Buyback-Pot Drain via Holder-Count Manipulation
Loss · ~2.13 BNB (~$1.24K) — drained from ETHFIN's on-contract BuybackPotBNB reserve
EthernalFinanceII.doBuyback() (EthernalFinanceII.sol:1940-1974) is declared public with no access control. It is supposed to be an internal maintenance routine that the…
GHT Exploit — Permissionless `transferFrom` Drains the Uniswap V2 Pair
Loss · ~$57K — 15.4386 WETH drained from the GHT/WETH pair
GHT is an ERC404 token (ERC20 + ERC721 hybrid) deployed behind an ERC1967 proxy. Its transferFrom(from, to, amount) implementation does not enforce the spender allowance…
Goat Tech — A user calling Controller::dctStake can bypass tax by first transferring the tokens to be staked
1. When a user stakes DCT via Controller.dctStake(amount_, receiver_, lockDuration_), a 1% tax is calculated from amount_ and burned to address(0xdead). 2. But the amoun…
IntrospectionToken (IT) Exploit — Inflationary Repricing Mint Drains the IT/USDT Pancake Pair
Loss · ~13,357 USDT (≈ $13.4K) drained from the IT/USDT PancakeSwap V2 pair
IntrospectionToken tries to defend its USDT price by minting free IT to the liquidity pool whenever someone buys IT out of the pool (mintToPoolIfNeeded, BEP20.sol:380-41…
JuiceStaking Exploit — Uncapped `stakeWeek` Bonus Multiplier Inflation
Loss · ~30.086 ETH (~$54K at the time), minted to the attacker as 332,238 JUICE and dumped into…
JuiceStaking.harvest() pays a staker pending + bonus, where bonus is computed as pending (stakingWeek - 1) 9 / 100 (contracts_JuiceStaking.sol:140). The stakingWeek valu…
LavaLending Exploit — WrapperOracle Price-Depeg Lets Manipulated LP Drain the Aave Pool
Loss · ~$340K — ~234K stablecoins (USDC + USDCe + USDT) + 20.33 WETH + 8.53 wstETH drained from…
LavaLending is an Aave-v3 fork on Arbitrum that lists a UniV3-wrapped USDC/USDCe LP token (USDC_USDC_LP at 0x10bdA0…) as collateral. Its value is supplied to the lending…
MO Token Exploit — Self-Recycling Borrow Burns Pool Reserves to Inflate `price()` and Drain USDT
Loss · ~572,316 USDT (~$572K) extracted from the Loan contract + the MO/USDT pair
The Loan contract prices its borrows off the live MO/USDT Uniswap-V2 pair via price() (contracts_Loan.sol:177-185). But every borrow() burns 90% of the borrowed MO direc…
ParaSwap AugustusV6 Exploit — Callback Hijack Drains Pre-Approved User Tokens
Loss · ~$24K (whitehat-recovered). PoC demonstrates the mechanism by siphoning 21,382.11 OPSEC w…
AugustusV6 implements Uniswap V3's uniswapV3SwapCallback as a public function with no access control at the entry point. Internally it only checks that the pool which ca…
Prisma Finance Exploit — Unauthorised `MigrateTroveZap` Flash-Loan Callback Drains Trove Collateral
Loss · ~$11M total on-chain; this PoC demonstrates the per-trove primitive (~1.282 wstETH ≈ $5.3…
MigrateTroveZap is a thin wrapper meant to let a Prisma borrower migrate their own trove between two TroveManagers for the same collateral. It implements the ERC-3156 on…
SSS Exploit — Self-Transfer Balance-Doubling Lets Attacker Mint Phantom SSS and Drain the WETH Pool
Loss · ~$4.8M — 1,393.21 WETH drained from the SSS/WETH Thruster pair
The SSS token overrides ERC-20's _update so it can apply buy/sell tax, but it writes the recipient balance from a stale snapshot taken before the sender side was debited:
Taiko — gas issuance is inflated and will halt the chain or lead to an incorrect base fee
1. TaikoL2.anchor() is called once per L2 block by a fixed system address, passing the current L1 block height (_l1BlockId). It recomputes the EIP-1559 base fee via _cal…
Taiko — Validity and contest bonds can be incorrectly burned for the correct and ultimately verified transition
1. Taiko's TransitionState for a block records one prover, one tier and one validityBond — whoever most recently proved (or re-proved / overrode) the transition. 2. LibP…
TGBS Exploit — Repeated Permissionless Pool Burns via Self-Transfer Draining the TGBS/WBNB Pair
Loss · ~$150K — 366.806 WBNB drained from the TGBS/WBNB PancakeSwap pair
TGBS is a tax-on-transfer token whose _transfer hook calls _burnPool() on every non-exempt, non-swap-pair transfer (contracts_tgbs.sol:903-906). _burnPool() destroys 0.3…
Unizen "UnizenIO2" Exploit — Arbitrary-Call `TradeAggregator.swap` Token Theft
Loss · ~$2.1M — 83,222.657 VRA plus residual balances of ~30 other tokens drained across the cal…
Unizen's TradeAggregator.swap(Info info, Call[] calls) (selector 0x1ef29a02) is the on-chain backend that the Unizen front-end uses to settle a user's quote. A legitimat…
Unizen Exploit — Arbitrary `call` in the Unizen Aggregator Drains Any User Who Approved It
Loss · ~$2.1M total across the attacker's transactions; this PoC reproduces one such tx, drainin…
Unizen's aggregator proxy exposes a swap(bytes, bytes) entry point (0x1ef29a02) that lets the caller embed arbitrary calldata under a "route" field. The aggregator blind…
WooFi (WooPPV2) Exploit — Slippage-Model Price Collapse Drain
Loss · ~$8M (≈ 522.3 WETH + 141,603 USDCe extracted net)
WooFi's WooPPV2 is a single-pool, oracle-priced swap venue. Every swap writes the trade's implied new price back into the Wooracle via postPrice(base, newPrice) (contrac…
WOOFi Swap — pool can be drained
1. WooPPV2 prices swaps via a PMM curve. Selling baseAmount of a base token computes a gamma (price-impact fraction) from the CURRENT oracle price, checks gamma <= maxGa…
ZongZi / ZZF Exploit — Manipulated-Price Reward Drain via `burnToHolder` + `receiveRewards`
Loss · ~$223K — 383.44 WBNB stolen from the ZONGZI token contract's BNB reserve
ZZF is a "burn ZONGZI tokens, receive BNB" reward contract. Its burnToHolder(amount) converts the burn size into BNB by calling the router's getAmountsOut(amount, [ZongZ…
ADC Exploit — Permissionless `calcStepIncome()` Drains the MainPool
Loss · ~18.1 ETH (attacker funded 18 ETH, walked away with 36.1 ETH) — DeFiHackLabs tags it "~20…
ADC is a "join-the-game-to-earn" Ponzi-style dApp. Users buy an ADC token via Ticket.buyADC(), then deposit ETH into MainPool.joinGame() to become a player. Players are…
Affine DeFi LidoLevV3 Exploit — Flashloan-Triggered `upgradeTo` Drains All Aave Collateral
Loss · 33.699 aEthwstETH (~$115K at the time) — the strategy's entire remaining Aave collateral
LidoLevV3 uses Balancer flashloans internally to rebalance and to migrate assets to a new strategy on upgrade. The Balancer callback receiveFlashLoan (LidoLevV3.sol:82-1…
Babyloogn Exploit — Permissionless Airdrop Drain via Zero-Value NFT "Stake"
Loss · ~2.24 WBNB (≈ $700 at the time) — drained from the Babyloogn/WBNB PancakeSwap pair
The Babyloogn project shipped an "airdrop" contract whose claim function (0xfbe81135) hands out 285 Babyloogn per call to any caller who (a) has approved the Airdrop as…
Blueberry Protocol Exploit — Oracle Decimal Mismatch Enables ~$1.4M Under-Collateralized Borrow
Loss · ~$1,375,900 in borrowed assets (8,616 OHM, 913,262 USDC, 6.866 WBTC) taken against ~$2,98…
Blueberry's money market is a Compound v2 fork. The Comptroller's getHypotheticalAccountLiquidityInternal values a borrow as oraclePrice borrowBalance and collateral as…
BurnsDeFi / BurnsBuild Exploit — Spot-AMM Price-Oracle Manipulation in `burnToHolder`
Loss · ~$67K — ~31.15 BNB drained from BurnsBuild plus ~64,310 BUSDT + ~56,299 Burns tokens sent…
BurnsBuild.burnToHolder(amount, invitation) lets a user "burn" Burns tokens and, in exchange, receive BNB from the contract. The amount of BNB the user is owed is comput…
Compound v2 cUNI Exploit — Stale-Oracle Discount Borrow (Open Oracle `UniswapAnchoredView`)
Loss · ~$439,537 in bad debt created across the Compound v2 cUNI market (this PoC demonstrates t…
Compound v2 prices cTokens via the Open Oracle UniswapAnchoredView (contracts_Uniswap_UniswapAnchoredView.sol:132-143). That contract stores a per-symbol prices[symbolHa…
DeezNutz (DN404) Exploit — Self-Transfer Balance Inflation in a Reflection-Fork of DN404
Loss · ~$170K — 47.14 WETH of genuine pool liquidity drained
DeezNutz is a fork of Vectorized's DN404 (hybrid ERC-20/ERC-721) that bolts a SafeMoon-style reflection accounting layer on top. The reflection layer rewrites the core _…
DN404 Exploit — Unguarded `init()` Lets Anyone Re-init a Vesting Proxy and Drain Its Tokens
Loss · ~169,577 USDT (~$170K) — realized by dumping the stolen 685,000 FLIX into the FLIX/USDT p…
The LinearVesting contract is deployed behind an OpenZeppelin TransparentUpgradeableProxy. Its init(initToken, initPeriods, initInterval) function — the one that sets to…
DualPools Exploit — Donation-Inflated Exchange Rate Lets 2 wei of dLINK Borrow the Whole Pool
Loss · ~$41,893 — assets borrowed across 5 DualPools markets (50.07 WBNB, 0.1716 BTCB, 3.99 ETH,…
DualPools is a Venus/Compound fork. Each money-market token (dLINK, dWBNB, …) prices its own shares with the classic Compound formula exchangeRate = (cash + totalBorrows…
EGGX Exploit — ERC404 Flash-Mintable NFTs Drain a Per-NFT Token Airdrop
Loss · 1.9878 WETH (~2 ETH) net to the attacker — paid out of the EGGX per-NFT airdrop reserve a…
EGGX is an ERC404 token: balances and NFTs are coupled. Every _getUnit() = 10000 1018 of fractional balance corresponds to exactly one NFT, and NFTs are minted/burned au…
Entangle Trillion — callback reentrancy drains bridge withdrawals
withdraw transfers a callback-capable token before decrementing tokenStorage. A receiver re-enters twice during the token callback, so a nominal 100-token withdrawal dra…
Entangle Trillion — Curve/Convex withdrawal selector typo freezes LP exits
The CurveCompoundConvexSynthChef integration calls convex.witdraw rather than Convex withdraw. The selector does not exist on the target contract, so a legitimate LP wit…
Entangle Trillion — dynamic delegatecall lets a compromised master drain Compounder
Compounder.compound accepts a callee and payload from its authorized master then runs the pair with delegatecall. If that master EOA is compromised, it can run arbitrary…
Entangle Trillion — missing Stargate allowance blocks LP deposits
StargateSynthChef deposits LP by asking the Stargate staking contract to pull tokens from the chef, but it never approves that spender. Every fresh deposit fails at tran…
Folks Finance — incorrect updates to `pool.depositData.totalAmount` during repay-with-collateral
1. When a borrower repays with collateral, LoanManagerLogic.updateWithRepayWithCollateral updates the pool's total deposits with pool.depositData.totalAmount -= principa…
GAIN (GainOS) Exploit — Path-Dependent `balanceOf` Rebase Bug Drains the AMM Reserve
Loss · ~6.4329 WETH (≈ 18 ETH per the PoC header / SlowMist; the on-chain fork drains the single…
GAIN is a "gamified rebasoor." Every holder is secretly placed on one of two teams — SideA or SideB — and a holder's reported balance is computed with a different diviso…
Game (TheGame / Anciliainc) Exploit — Reentrancy + Stale `bidEther` Refund in `makeBid()`
Loss · ~20 ETH (on-chain). The extracted PoC scales the seed capital to 0.6 ETH and turns it int…
Game's auction lets anyone outbid the current high bid via makeBid(). When a new bid arrives, the contract first refunds the previous high bidder their full bidEther and…
MINER (ERC-X / ERC404-style) Exploit — Fractional-Transfer NFT Mint/Burn Asymmetry Drains the Uniswap V3 Pool
Loss · ~$140 ETH reported by the original disclosure; the reproduced PoC at this fork block nets…
MINER is an "ERC-X" hybrid (the same family as ERC-404): one contract that is simultaneously an ERC-20 and an NFT collection. Every tokensPerNFT = 1e18 units of the ERC-…
MINER (ERC404) Exploit — Self-Transfer Balance Inflation via `skim()`
Loss · ~3.5 WBNB (≈ the entire WBNB side of the MINER/WBNB pool)
MINER is an "ERC404"-style hybrid that keeps both an ERC20 ledger (_balances) and an ERC1155/721 NFT ledger, minting/burning NFTs as a holder's ERC20 balance crosses who…
Pandora's Nodes 404 Exploit — `transferFrom` Allowance Underflow Lets Anyone Move Tokens Out of the Pool
Loss · ~$17,000 — 7.548 WETH drained from the BLOCK/WETH Uniswap V2 pair
PandorasNodes404 is an early ERC404 token (the experimental "mixed ERC20/ERC721" standard). Its transferFrom (contracts_ERC404.sol:206-259) has a fatal authorization hol…
Particle Trade Exploit — Forged-Lien `accountBalance` Mint via `onERC721Received`
Loss · ~50.1 ETH per draining lien (PoC withdraws 50.126827091960426151 ETH); the live incident…
ParticleExchange is an NFT margin-trading / lending protocol. To save users a separate setApprovalForAll, it overrides onERC721Received so that an NFT transfer can piggy…
Rio Network — `reportOutOfOrderValidatorExits` does not update the utilization heap order
1. reportOutOfOrderValidatorExits() increases an operator's exited count when validators exit the beacon chain outside the normal withdrawal-driven flow. 2. This changes…
Rio Network — malicious operators can `undelegate` theirselves to manipulate the LRT exchange rate
1. RioLRTOperatorDelegator.getEigenPodShares() is a direct, live pass-through read of EigenLayer's EigenPodManager.podOwnerShares() for the delegator's own EigenPod — no…
Rio Network — requested withdrawal can be impossible to settle due to EigenLayer share value appreciation
1. RioLRTCoordinator.requestWithdrawal() converts the withdrawal amount to a fixed number of EigenLayer shares, using the exchange rate at request time, and records that…
Rio Network — setting the strategy cap to 0 does not update total shares held or the withdrawal queue
1. OperatorRegistryV1Admin.setOperatorStrategyCap(operatorId, 0) — used both directly and when deactivating/removing an operator — queues the operator's full allocation…
RuggedArt (RuggedMarket) Exploit — Reentrant `targetedPurchase` Buys NFTs With Self-Staked Collateral
Loss · ~1.024 WETH (≈ $3.5K at the time) drained from the RUGGED/WETH Uniswap V3 pool
RuggedMarket.targetedPurchase(tokenIds, swapParam) (src_Market.sol:277-289) is meant to: take ETH from the caller, swap it for RUGGED via the Uniswap Universal Router, a…
Seneca Protocol Exploit — Arbitrary External Call Abuses User Approvals
Loss · ~$6.4M total (all users who had approved a Seneca Chamber). PoC drains one victim: 1,385.…
Seneca's Chamber lending contract exposes a generic batch executor, performOperations(actions, values, datas) (contracts_Chamber2.sol:408-485). One of the supported acti…
SMOOFS Staking Exploit — Reentrant `Withdraw()` Drains the Reward-Token Pool via `safeTransferFrom` Callback
Loss · The attacker walked away with a net +4,350 MOOVE in this PoC slice (52,850 → 57,200 MOOVE…
SMOOFSStaking.Withdraw() returns a staked NFT to the caller with nftCollection.safeTransferFrom(address(this), msg.sender, _tokenId) and only afterwards pays out the car…
Swarm Markets (XToken) Exploit — Public `mint()` / `burnFrom()` Mint-and-Unwrap Drain
Loss · ~$7,733 — 7,729.32 DAI + 3.516232 USDC drained from the XTokenWrapper
Swarm Markets wraps real ERC20 collateral (DAI, USDC) into 1:1 "xTokens" through an XTokenWrapper. The wrapper is the sole intended minter: wrap() pulls in the underlyin…
Tapioca DAO — Incorrect math means removeAssetFromSGL will never work once SGL has accrued interest
1. A user asks the Magnetar periphery helper to withdraw a specific amount of the underlying asset from a Singularity market via removeAssetFromSGL. 2. Magnetar converts…
Tapioca DAO — Magnetar grants YieldBox approval but markets only accept pearlmit
UntaggedMagnetar grants YieldBox approval but markets only accept pearlmit. Harm demonstrated: Magnetar deposit/lend permanently fails — wrong approval mechanism vs pearlmit.
Tapioca DAO — mintBBLendXChainSGL compose data.user not bound — force-lend victim
UntaggedmintBBLendXChainSGL compose data.user not bound — force-lend victim. Harm demonstrated: Whitelisted USDO compose forces lend of victim tokens into Magnetar.
Tapioca DAO — OFT self-call makes Magnetar msg.sender and bypasses _checkSender
UntaggedOFT self-call makes Magnetar msg.sender and bypasses _checkSender. Harm demonstrated: Nested OFT self-call drains victim collateral approved to Magnetar.
Tapioca DAO — Unwhitelisted marketHelper returns malicious removeCollateral payload
UntaggedUnwhitelisted marketHelper returns malicious removeCollateral payload. Harm demonstrated: Malicious marketHelper steals victim collateral via Magnetar approval.
ZoomerCoin Exploit — Spot-Priced Upfront Staking Reward Drained via AMM Price Manipulation
Loss · ~14.39 ETH — drained from the ZOOMER staking contract's ETH balance (4 successful claims…
The ZOOMER staking contract at 0x9700204D… exposes a deposit function (selector 0x72c4cff6(address token, uint256 amount)) that, at the moment of deposit, values the dep…
Abracadabra / MIM Spell V2 Exploit — `repayForAll` Rebase De-sync + Rounding-Up Debt Inflation
Loss · ~$6.5M — attacker walked off with 349,003.46 MIM + 1,807.68 WETH (post-laundering balance…
Abracadabra's CauldronV4 tracks all borrower debt in a single BentoBox-style Rebase struct, totalBorrow { uint128 elastic; uint128 base; } (CauldronV4.sol:89). elastic i…
Barley Finance Exploit — Flash-Loaned Collateral Double-Counted as `bond()` Deposit
Loss · ~$130K — 52.13 WETH (drained 7,876,244 BARL from the wBARL index, swapped via DAI to WETH)
wBARL is a "podded" index token: you bond() underlying BARL into it and receive wBARL share tokens 1:1 (minus a 1% fee); you debond() your wBARL to redeem a pro-rata sli…
Bridge Mutual `BMIZapper` Exploit — Arbitrary External Call Drains Pre-Approved User Funds
Loss · 114,146.247097 USDC (~$114K) drained from a single victim
BMIZapper.zapToBMI() lets a caller pass an arbitrary _aggregator address together with an arbitrary _aggregatorData byte string. Deep in the conversion path, the zapper…
Citadel Finance Exploit — Spot-Price Oracle Manipulation in `CitadelRedeem.redeem()`
Loss · ~$93K total across several redeem txs; this PoC reproduces one redeem netting ≈ 21.33 WET…
CitadelRedeem.redeem() lets a staker burn their redeemable CIT and receive an equivalent amount of the treasury's WETH. To convert "CIT worth $X" into "amount of WETH",…
DAO SoulMate Exploit — Permissionless `redeem()` Drains the DAO's SetToken Basket
Loss · ~$319K — the full underlying basket of an 18-token Set (USDC, DAI, WETH, UNI, AAVE, MATIC…
The "SoulMate" DAO contract owns 2,786.53 BUI — units of a Set Protocol index token (BUI) that is collateralized by a basket of 18 blue-chip ERC20s held inside the SetTo…
Decent — Anyone can update the Router address in `DcntEth`
1. DcntEth gates mint/burn with onlyRouter, but setRouter is public and unrestricted. 2. Anyone can point router at themselves, mint arbitrary DcntEth, and call DecentEt…
Decent — Failed `execute` refunds a phantom source-adapter address
Untagged1. Source DecentBridgeAdapter calls the router; _getCallParams packs msg.sender (the adapter) as from. 2. Destination onOFTReceived → executor.execute(_from, _to, ...).…
Decent — Missing min-gas checks permanently block the LayerZero channel
1. Adapter gas is 100_000 + _dstGasForCall with no floor on the user parameter. 2. A malicious or mistaken user can pass ~1000 → destination OOGs / fails. 3. LayerZero t…
Freedom (FREE / FREEB) Exploit — Slippage-less Treasury Buy at an Attacker-Manipulated Price
Loss · ~74.15 WBNB (≈ the BNB the FREEB "market-cap" contract wasted buying FREE high)
FREEB is the "market-cap management" sidekick of the FREE token. It holds BNB in its own treasury and exposes a permissionless buyToken(uint256 listingId, uint256 expect…
Gamma Strategies (UniProxy / Hypervisor) Exploit — Spot-Price Vault-Share Inflation
Loss · ~$6.3M across Gamma's affected Hypervisors (multiple vaults drained in the incident). Thi…
Gamma's Hypervisor is an automated Uniswap-V3/Algebra liquidity-manager. Users deposit token0+token1 through UniProxy.deposit; the proxy asks Clearing.clearDeposit to va…
INIT Capital — fillOrder executor front-run via limitPrice_e36
1. fillOrder computes amtOut from order.limitPrice_e36 (creator's slippage param). 2. On the "long base, coll ≠ tokenOut" branch, amtOut = ceil(coll * limit / 1e36) - re…
INIT Capital — MarginTradingHook#updateOrder lacks access control
1. MarginTradingHook.updateOrder(_posId, _orderId, ...) resolves the CALLER's own initPosId from _posId and checks only that it is non-zero (that the caller owns SOME po…
INIT Capital — Order creator can update tokenOut to arbitrary token
1. createOrder enforces tokenOut ∈ {baseAsset, quoteAsset}. 2. updateOrder rewrites order.tokenOut with no such check. 3. Executors commonly pre-approve the hook for man…
LMCV — failed Hyperlane message replay mints dPRIME repeatedly
A failed Hyperlane transfer remains in failedMessages after retry succeeds. The exact same origin, recipient, and nonce can be retried repeatedly, minting the amount aga…
LQDX / LiquidXv2Zap Exploit — Arbitrary-`account` `deposit()` Spends Anyone's Approval
Loss · Every WETH (or any token) a user has approved to the Zap is spendable by anyone. This PoC…
LiquidXv2Zap.deposit() lets the caller pass an arbitrary account address and then pulls funds from that account via safeTransferFrom (contracts_LiquidXv2Zap.sol:397-440):
MIC Token Exploit — LP-Fee Distributor Pays the Same LP Tokens Over and Over
Loss · ~$500K cumulative on-chain (SlowMist); the forked single-tx PoC recovers 1,876.86 BUSDT n…
MICToken accrues a "LP fee" in amountLPFee (a slice of every buy's volume). Anyone can call the public swapManual(), which calls swapAndSendLPFee(msg.sender). That funct…
NBLGAME (NblNftStake) Exploit — ERC721 `onERC721Received` Reentrancy Double-Withdraw
Loss · ~$180K — 164,967.66 USDT + 6.90 WETH extracted (the stake contract's entire 1,773,100,000…
NblNftStake.withdrawNft() returns a slot's staked NFT and staked NBL to the caller, but it performs the asset transfers before it clears the slot's stored amounts (NblNf…
Orbit Chain Bridge Exploit — Forged Validator Signatures Drain the ETH Vault
Loss · ~$81.5M total across 5 assets (ETH, WBTC, USDT, USDC, DAI). This PoC reproduces the WBTC…
Orbit Bridge mints/releases assets on the destination chain only after a quorum of validator signatures is presented to the vault's withdraw(). The ETH vault verifies th…
Peapods Finance Exploit — Free Index-Token Mint via `flash()` + `bond()` Self-Collateralization
Loss · ~$1K (PoC extracts 0.1256 WETH + dust; protocol's PEAS backing siphoned, index ppPP suppl…
DecentralizedIndex (the base of every Peapods pod, here the WeightedIndex instance "ppPP") exposes a fee-only flash loan of its own underlying index asset — flash() (con…
Radiant Capital Exploit — Empty-Market `liquidityIndex` Inflation + `rayDiv` Rounding Drain
Loss · ~$4.5M total across markets; this PoC realizes 90.055 WETH (≈ the WETH borrowed against a…
Radiant is an Aave-V3 fork. Each reserve tracks a liquidityIndex (a RAY-scaled, 1e27 share price): a depositor's true balance is scaledBalance · liquidityIndex / RAY, an…
Rio Vesting Escrow — vaults can be bricked by selfdestruct()ing implementations
1. Every Rio escrow "clone" is a thin proxy that DELEGATECALLs a single SHARED implementation contract for all of its logic. 2. That implementation reads its own factory…
SHELL MEV-Bot Drain — Permissionless Arbitrage Function with Attacker-Chosen Recipient
Loss · ~$1,000 (≈ 1,250 BUSD of the victims' stablecoin balances; SlowMist lists ~$1K). Two MEV-…
Two BSC MEV/arbitrage bots ("Robot1", "Robot2") expose a permissionless function with selector 0x5f90d725. The bot owners had pre-approved the bots to spend their BUSD a…
Socket Gateway Exploit — Arbitrary `call` in `WrappedTokenSwapperImpl` Drains User Approvals
Loss · ~$3.3M across all approved users (multi-victim sweep). The PoC reproduces a single victim…
SocketGateway is a router whose executeRoute(routeId, routeData) blindly delegatecalls into the route implementation at routes[routeId] (src_SocketGateway.sol:87-102). A…
Subsquid — Gateway creator can steal all tokens from the GatewayRegistry
Untagged1. Stake tokens into a gateway; after unlock, unstake them. 2. Unregister the gateway — Gateway struct deleted, stakes[] kept. 3. Re-register the same peerId — totalUnst…
Wise Lending — Lending-Share Price Inflation via Deposit/Withdraw Rounding Asymmetry
Loss · ~$464,000 (live incident, multiple drained pools)
WiseLending is a share-based money market. Each lending pool tracks two numbers — a token accumulator pseudoTotalPool and a share accumulator totalDepositShares — and th…
Wise Lending Exploit — Lending-Share Price Inflation via Rounding Asymmetry + Bad-Debt Donation
Loss · ~$464K — ~73.50 WETH + 93.79 wstETH + ~469.4 LPT (Pendle wstETH LP) drained from the pool
WiseLending is a pooled lending market where each pool tracks two scalars, pseudoTotalPool (the underlying owed to all lenders) and totalDepositShares (the receipt share…
XSIJ (GGGTOKEN) Exploit — Repeatable, Un-reset `autoBurnLiquidityPairTokens()` Pool Drain
Loss · ~51,722.57 USDT (≈ $51.7K) drained from the XSIJ/USDT PancakeSwap pair
GGGTOKEN (XSIJ) is a meme/fee token with an "auto-nuke LP" mechanic. Whenever someone sells XSIJ into the pair, _transfer checks a state variable removePoolAmount and, i…
ZeroLend — `ZeroLocker.merge()` lets a staker inflate veNFT voting power ~9×
1. ZeroLocker is a Solidly/Curve-style voting-escrow veNFT: locking ZERO mints an NFT whose voting power (balanceOfNFT) decays linearly over the lock. 2. To stop flash-v…
ZeroLend — Incorrect reward distribution when t == roundedTimestamp
Untagged1. At an exact epoch boundary, t == roundedTimestamp. 2. The loop uses > so it still writes veSupply[t] from the current locker point. 3. Bob locks more after the checkp…
ZeroLend — Missing access control in afterLockUpdate
Untagged1. afterLockUpdate is intended to be called only by ZeroLocker after lock changes. 2. It is external with no caller restriction. 3. Anyone holding pool tokens can self-r…
BCT Token Exploit — Self-Funding Referral-Reward Drain of the Promotion Pool
Loss · ~10.15 BNB profit to attacker (drained from the BCT promotion-reward pool, monetized via…
BCT is a "DeFi tokenomics" ERC20 with a multi-level marketing (MLM) referral system. On every buy or sell routed through its liquidity pair, the token pays referral bonu…
Beanstalk BIP-39 upgrade omits a modified facet, inflating grown Stalk 1,000,000x
Beanstalk Silo — legacy milestone stem decimal mismatch
The upgrade moves gauge points to untruncated precision but leaves historic milestone stems truncated. Stem tip adds those incompatible units and depositors lose accrued…
BEARN/Bvaults `convertDustToEarned()` Exploit — Permissionless, Slippage-Free Dump of a Strategy's "Dust" Balance
Loss · ~$769K — attacker walked away with 761,101.18 BUSD + residual WBNB (~$10K) after fully re…
BvaultsStrategy is an Alpaca-yield "auto-compound" strategy. Its housekeeping routine convertDustToEarned() is meant to mop up leftover want tokens (BUSD) by swapping th…
BOBO_BOY (BOB) Exploit — Broken `_transfer` Fee Branches Desync Pool Reserves
Loss · ~3.008 BNB profit drained from the BOB/WBNB PancakeSwap pair (PoC header: "~3 BNB")
BOBO_BOY is a fee-on-transfer token whose _transfer (BOBO_BOY.sol:470-503) splits its fee logic into two independent if blocks — one for isMarket(from) (a "buy"), one fo…
bZx / Fulcrum `iToken` Exploit — Empty-Pool Share-Price Inflation (ERC4626-style Donation Attack)
Loss · ~$208K — drained the iETH, iWBTC (and other) Fulcrum lending pools
A Fulcrum iToken is a yield-bearing lending share, priced as tokenPrice = underlyingHeld * 1e18 / totalSupply (LoanTokenLogicStandard.sol:848-860). When totalSupply and…
CCV Exploit — Permissionless Treasury-Proxy Forced Liquidation Sandwich
Loss · ~3,207.63 BUSD drained from two protocol-owned treasury proxies via a sandwiched forced s…
The CCV protocol parks its working liquidity in two upgradeable proxy contracts:
Channels Finance Exploit — Compound-Fork Exchange-Rate Inflation via Donated Underlying
Loss · ~$320,000 across 7 markets (WBNB, BUSD, USDT, USDC, DAI, ETH, BTCB)
cCLP_BTCB_BUSD is a Channels Finance money-market backed by the PancakeSwap BTCB/BUSD LP token as its underlying. Like every Compound-v2 cToken, its exchange rate is
Channels Finance Exploit — cToken Exchange-Rate Inflation via Direct LP Donation + LP-Oracle Manipulation
Loss · ~$4.4K — attacker walked away with 1,283.97 BUSD + 3,128.84 USDC (≈ $4.41K) of pool liqui…
Channels Finance is an unverified Compound v2 fork on BSC. One of its markets, cCLP_BTCB_BUSD (0x9379…8F4C), accepts a PancakeSwap BTCB/BUSD LP token as collateral and p…
Collective (Revolution Protocol) — `VerbsToken.tokenURI()` JSON injection via unsanitized `CultureIndex.createPiece()` metadata
1. CultureIndex.createPiece() stores an art piece's ArtPieceMetadata — including image and animationUrl — verbatim, with no check for JSON-breaking characters (", :, ,).…
Collective (Revolution Protocol) — malicious delegatees can permanently block delegators from redelegating or transferring their NFTs
1. OpenZeppelin's original Votes.delegates(account) returns $._delegatee[account] verbatim — including address(0) when the account never delegated. 2. Revolution Protoco…
DominoTT Exploit — thirdweb `Multicall` + `ERC2771` `_msgSender()` Spoofing Burns the Pool's Tokens
Loss · ~4.84 WBNB net profit to the attacker (≈5 WBNB drained from the DominoTT/WBNB pair); fund…
"DominoTT" is a thirdweb TokenERC20 — an off-the-shelf ERC20 that bundles three features that compose into a critical hole:
Elephant Money (ElephantStatus) Exploit — Spot-Price Oracle Manipulation of `sweep()`
Loss · ~$114K — 114,385.96 BUSD extracted (PoC). DeFiHackLabs header cites ~$165K total across t…
Elephant Money runs a "bonding/treasury" mechanism (the ElephantStatus contract behind Elephant.sweep()). Periodically — and permissionlessly — anyone can call sweep().…
FCN-TRUST Staking Exploit — Unverified Staking Contract Pays Unbounded FCN Rewards Drained Through a Pre-Inflated FCN/BUSDT Pool
Loss · ~$500K — the FCN/BUSDT PancakeSwap pool's ~512,963 BUSDT reserve was drained
The FCN-TRUST staking contract at 0x431Abb… (deployed unverified) lets users "stake" by burning tiny amounts of four project tokens (KLEN, TRUST, MDAO, FCN) and then cla…
Floor Protocol Exploit — Permissionless `extMulticall()` Drains User-Approved NFTs
Loss · ~$1.6M total across all victims (BAYC, MAYC, Pudgy Penguins, …). This PoC reproduces one…
Floor Protocol ("Flooring Lab") fractionalises blue-chip NFTs. To deposit, users setApprovalForAll on the FlooringPeriphery contract so it can pull their NFTs into the p…
GoodDollar `GoodCompoundStaking` Exploit — Slippage-Free COMP Reward Swap into a Pre-Manipulated Pool
Loss · ~$13K — 250.63 COMP extracted (attacker COMP balance 7.42 → 258.05)
GoodDollar's GoodCompoundStaking contracts earn COMP from supplying assets to Compound. When interest is harvested, the staking contract sells its entire COMP reward bal…
GoodDollar Exploit — Unvalidated `collectInterest` Staking-Contract Callback → Reentrant Bonding-Curve Drain
Loss · ~$2M — drained from the GoodDollar reserve as 625,140.23 DAI + 10,213,394,832.90 G$ (Good…
GoodDollar's GoodFundManager.collectInterest(address[] _stakingContracts, bool _forceAndWaiverRewards) is a permissionless keeper function that loops over a caller-suppl…
HNet Exploit — ERC-2771 + Multicall `_msgSender()` Spoofing Burns the Pool's Tokens
Loss · ~2.4 WBNB drained from the HNet/WBNB pool in the live attack (~$550 at ~$230/WBNB). This…
HNet is a clone of thirdweb's TokenERC20 preset. That preset inherits both ERC2771ContextUpgradeable (meta-transaction support) and MulticallUpgradeable (TokenERC20.sol:…
HYPR Exploit — Uninitialized `L1StandardBridge` Proxy → Cross-Domain Messenger Spoof → Bridge Drain
Loss · ~$200,000 — 2,570,000 HYPR drained from the project's L1 standard bridge
HYPR deployed an OP-Stack L1StandardBridge behind a legacy L1ChugSplashProxy, but the proxy was never initialized. The bridge implementation's initialize(CrossDomainMess…
INIT Capital — liquidations can be prevented by frontrunning and liquidating 1 debt
1. PosManager.updatePosDebtShares does extraInfo.totalInterest += (debtAmtCurrent - extraInfo.lastDebtAmt), commented // NOTE: debtAmtCurrent is always >= lastDebtAmt. 2…
INIT Capital — MoneyMarketHook#_handleRepay can leave user tokens stuck
1. MoneyMarketHook._handleRepay converts the caller-supplied _params[i].shares into repayAmt via debtShareToAmtCurrent and transferFroms that full amount from the user i…
INIT Capital — wLp tokens could be stolen
1. PosManager.removeCollateralWLpTo(_posId, _wLp, _tokenId, _amt, _receiver) only checks that _posId actually holds _tokenId inside the newWLpAmt == 0 branch — i.e. only…
KEST (KEKESANTA) Exploit — Fee-on-Transfer Reserve De-Sync + `skim()` Pool Drain
Loss · ~$2.3K — 9.295 WBNB drained from the KEST/WBNB PancakeSwap pair (attacker net profit 9.11…
KEKESANTA (KEST) is a deflationary BEP-20 that charges a 2% fee on every buy and sell against its own PancakeSwap pair. Crucially, the fee is applied to the recipient cr…
MAMO (Matmo) Exploit — Permissionless Mint via Whitelisted `BuyToken` → `giveawayOne`
Loss · ~$3.3K — attacker netted 5.7958 WBNB + 95,000,000 MAMO; the MAMO/USDT pair was drained of…
The MAMO token exposes two mint-like functions, giveaway() and giveawayOne() (MAMO.sol:329-382), that emit Transfer(0x0, addr, amount) and credit a "treasury" balance fo…
NFTTrader Exploit — Reentrancy via `editCounterPart()` During Swap Settlement
Loss · ~$3M total across victims (per hacked.slowmist.io); this PoC drains 5 CloneX NFTs from on…
NFTTrader is a peer-to-peer NFT swap escrow. A user creates a swap intent listing the NFTs they offer (nftsOne) and the NFTs they expect from a counterpart (nftsTwo), an…
PHIL (PhilC) Exploit — Public, Unrestricted `simpleToken()` Mint Drains the AMM Pool
Loss · ~2.0987 WBNB (~$510 at the Dec-2023 BNB price) drained from the PHIL/WBNB PancakeV3 pool
PHIL exposes a public, parameter-less function simpleToken() that mints the entire initial token supply — 120,000,000 PHIL — directly to msg.sender, with no access contr…
Pine Protocol Exploit — Shared-Vault `flashLoan` Invariant Bypassed by Cross-Pool `repay()`
Loss · ~$90K total (per hacked.slowmist.io); the PoC reproduces the drain of NFT id 3324 alone —…
Pine Protocol runs two NFT lending pools (an "old" ERC721LendingPool02 and a "new" one) that share the same lender vault (_fundSource = 0xc490…037e, a Gnosis Safe). Each…
Revolution / Collective — art-piece quorum inflated by auctioned ERC721 voting power
1. createPiece sets totalVotesSupply from erc20.totalSupply() + weighted erc721.totalSupply(). 2. The ERC721 currently held by AuctionHouse is included but cannot vote f…
Stake.Link reSDL bridge — stale approval steals returned lock
handleOutgoingRESDL removes the lock owner but does not delete its transfer approval. When the same ID returns to a victim, the stale approved account transfers the lock…
Stake.Link rewards — incoming bridge update makes rewards insolvent
The controller's effective balance is increased before its already accrued rewards are checkpointed. It then claims old rewards on newly added stake, exceeding the funde…
Telcoin Exploit — Uninitialized `CloneableProxy` Hijacked via Public `initialize()`
Loss · ~$1.24M total across the incident; 6,018,296.75 TEL drained from this one proxy clone in…
Telcoin deployed a fleet of upgradeable CloneableProxy contracts as EIP-1167 minimal clones that forward all calls to a shared logic contract 0x10d0…E853. That logic exp…
TIME (ChronoTech) Exploit — ERC-2771 + Multicall Arbitrary `_msgSender()` Spoofing → Pool-Reserve Burn
Loss · ~84.59 ETH (≈ $185K at the time) — gross +89.51 WETH drained from the TIME/WETH Uniswap-V…
The thirdweb TokenERC20 is both an ERC-2771 meta-tx recipient (it trusts a Forwarder and reads the transaction's logical sender from the last 20 bytes of calldata) and a…
Transit Finance (TransitSwap V5) Exploit — Forged "Pool" in `exactInputV3Swap` Drains Router-Held Funds
Loss · ~$43,841 — 43,841.87 USDT held by the router, swapped out as 173.907 BNB to the attacker.…
TransitSwapRouterV5.exactInputV3Swap() lets the caller pass an arbitrary list of "pools" (params.pools[]). For each entry the router (1) reads token0()/token1()/fee() of…
"bot" / MEV-bot Router Exploit — Permissionless, Zero-Slippage Forced Swaps + Sandwich Drain
Loss · ~$2,000,000 (per PoC header) — in this fork-block reproduction the attacker nets 819.63 W…
The victim is an unverified MEV/arbitrage bot router that held a working inventory of stablecoins and blue-chips (USDC, USDT, WBTC, WETH) and exposed a helper, selector…
3913 Token Exploit — `skim`-Driven Invite-Bonus / LP-Burn Vault Drain
Loss · ~31,354 USD (31,354.82 BUSD, single tx; this was one of several attack txs)
3913 is a deflationary "MLM/dividend" token. Its _transfer (T3913.sol:909-995) wires three independent payout mechanisms onto plain ERC20 transfers:
9419 (8633/0cCa) Exploit — Permissionless `autoAddLp()` / `autoSwapAndAddToMarketing()` Reserve Manipulation
Loss · ~$52K (per the PoC @KeyInfo header); net attacker take this run ≈ 26,362 USDT transferred…
Coin9419 (V2 = 0x0cCa…, V3 = 0x8633…) is a "tax token with DeFi features." On every taxed transfer it pokes two external helper contracts:
AI SPACE (AIS) Exploit — Permissionless `PendingMint` Inflation + Unprotected Vault Drain
Loss · ~$60.7k — 60,686.88 USDT extracted from the AIS/USDT PancakeSwap-V2 pair
The AIS token bolts a "market reward" mint mechanism onto a standard OZ ERC20. Every transfer that touches a registered AMM pair bumps a global counter PendingMint by 4–…
Alchemix — `FluxToken.calculateBPT` uses wrong algorithm causing `nftClaim` revenue to be 10,000x higher than expected
Untagged1. FluxToken.bptMultiplier = 40 is documented as representing 0.4% (40 out of 10,000 bps). 2. calculateBPT(_amount) returns _amount * bptMultiplier without ever dividing…
Alchemix — `getActualSupply` should be used instead of `totalSupply` for Balancer pools
Untagged1. _depositIntoBalancerPool computes the join's bptAmountOut (the minimum-output / slippage-protection floor) from IERC20(balancerPool).totalSupply(). 2. Real Balancer p…
Alchemix — `RevenueHandler.checkpoint` counts unclaimed rewards as new rewards
1. RevenueHandler.checkpoint() runs once per epoch and, for a revenue token with no poolAdapter set, records amountReceived = thisBalance where thisBalance = IERC20(toke…
Alchemix — `RevenueHandler.checkpoint` isn't correct when `poolAdapter` is 0
1. RevenueHandler.checkpoint(), for a revenue token with poolAdapter == address(0) (a plain, non-alchemic token like DAI), sets amountReceived = thisBalance and does epo…
Alchemix — Attacker can gain infinite FLUX by repeating this attack!
Untagged1. Voter.reset(tokenId) is capped to once per epoch per tokenId by onlyNewEpoch. It calls veALCX.abstain(tokenId) (sets voted = false) and then accrues FLUX proportional…
Alchemix — BPT can be locked for only 1 week, resulting in unfair ALCX reward distribution
1. VotingEscrow._createLock is supposed to enforce a minimum lock period of 1 epoch (2 weeks): require(unlockTime >= (((block.timestamp + EPOCH) / WEEK) * WEEK), ...). 2…
Alchemix — infinite minting of FLUX through `voter.poke()`
1. poke(tokenId) calls _vote(tokenId), which unconditionally calls FluxToken.accrueFlux(tokenId). 2. accrueFlux does unclaimedFlux[tokenId] += claimableFlux(tokenId) — i…
Alchemix — insolvency in `RevenueHandler.sol` because unclaimed revenue is re-counted
1. RevenueHandler.checkpoint() runs once per epoch, reads the contract's current token balance, and records it as this epoch's revenue. 2. For non-alchemic-tokens: amoun…
Alchemix — loss of unclaimed bribes after burning a veALCX token
1. A veALCX holder votes for a pool through Voter.vote(). The pool's Bribe contract earns them third-party reward tokens (e.g. BAL) for that epoch. 2. When the lock expi…
Alchemix — malicious user can mint unlimited FLUX tokens
1. Users earn FLUX proportional to their veALCX's current locked value. Calling Voter.reset(tokenId) adds claimableFlux(tokenId) to the token's unclaimed FLUX balance —…
Alchemix — newly created gauge may miss out on its rewards
1. Voter._distribute(gauge) starts by reading _claimable = claimable[gauge] into memory, then resets claimable[gauge] to 0, THEN calls _updateFor(gauge) — the function t…
Alchemix — Precision loss causes minor loss of FLUX when claiming with NFTs
1. getClaimableFlux computes claimableFlux = (((bpt veMul) / veMax) veMax (fluxPerVe + BPS)) / BPS / fluxMul;. 2. The / veMax immediately followed by veMax is a no-op in…
Alchemix — slippage protection is inaccurate (`RevenueHandler._melt`)
1. RevenueHandler._melt(revenueToken) swaps revenueTokenBalance of a revenue token (e.g. WETH) for its paired alAsset (e.g. alETH) through a pool adapter. 2. It passes r…
Alchemix — Stuck yield tokens upon withdrawal of votes from Bribe contract
Untagged1. Bribe.deposit(amount, tokenId) increments totalSupply, balanceOf[tokenId], and totalVoting. 2. Bribe.withdraw(amount, tokenId) decrements totalSupply and balanceOf[to…
Alchemix — unauthorized minting of unlimited FLUX in 1 transaction
1. A veALCX position accrues FLUX once per epoch by calling voter.poke(tokenId), which internally calls _vote() → FluxToken.accrueFlux(tokenId). 2. poke() is missing the…
Alchemix — voters who withdraw veALCX tokens risk losing gained bribes
1. To close out a veALCX position, the documented sequence is: (i) Voter.reset(tokenId) if the position has voted, (ii) VotingEscrow.startCooldown(tokenId), (iii) wait f…
BrandPad (BRAND) Exploit — Permissionless `buyToken()` Buyback-Bot Sandwich
Loss · ~23.18 WBNB profit to the attacker; ~25.3 BNB drained from the BRAND buyback bot
The BRAND project deployed a "buyback" / market-maker bot at 0x831d6F…EEeFD4 and pre-funded it with ~25.3 BNB. The bot exposes a function buyToken() (selector 0xa4821719…
Burntbubba (LevX / FarmingLPToken) Exploit — Spot-Price Share Minting Manipulated via Attacker-Created Routing Pools
Loss · ~$3K — 1,597.51 USDC + 0.6549 WETH extracted by the attacker contract (≈ the underlying U…
FarmingLPToken is an ERC-4626-flavoured wrapper that takes a SushiSwap LP token (here the USDC/WETH pair), farms it in MasterChef, and mints "fLP" shares to the deposito…
CAROL Protocol Exploit — Reentrancy in `sell()` via Mid-Function ETH Payout to Attacker
Loss · ~$53K — attacker ended with 28.471 ETH (net +28.40 ETH) from a 0.07 ETH stake
CAROLProtocol.sell() is a "burn my receipt → get ETH" function. It does three things in order:
EEE-COIN Exploit — Flash-Loan Reserve Manipulation via a Compromised LP-Holder Router
Loss · ~$22,814 USDT (22,840.94 USDT net to the attacker)
EEECOIN is a fee-on-transfer ("tax") token whose EEE/USDT PancakeSwap pair had no defence against reserve manipulation. A helper router (swap_router 0x5002F2D9…) — which…
EHX (Eterna) Exploit — Fee-on-Transfer / AMM `skim` Drain
Loss · Not separately quantified by the project (@KeyInfo - Total Lost : Unclear). The PoC recov…
Eterna (EHX) is a fee-on-transfer token: every transfer between non-excluded accounts silently skims 25% of the moved amount into the token contract itself (Token.sol:11…
FiberRouter Exploit — Arbitrary External Call Drains a Victim's Token Approval
Loss · ~59.01 USDC stolen from a single victim in this tx (the bug is generic — every account th…
FiberRouter.swapAndCrossOneInch() is meant to perform a local 1inch swap and then forward the proceeds cross-chain. To execute the "1inch swap," it makes a raw low-level…
GROK Token Exploit — Fee-on-Transfer Tax Auto-Swap Reserve Desync
Loss · ~26.39 WETH (≈ $50K at the time) drained from the GROK/WETH Uniswap-V2 pair
GROK is a stock "meme-token" template: a 24% transfer tax that accrues into the token contract, plus an automatic tax-swap (swapTokensForEth, GROK.sol:272-284) that dump…
KR Token Exploit — Permissionless `sellKr()` Liquidity-Pool Drain
Loss · ~15,223 BUSD (≈$15,223) drained from the KR/BUSD PancakeSwap pair
The KR token contract holds the LP tokens for its own KR/BUSD PancakeSwap pair — i.e. the project's liquidity was parked in the token contract rather than time-locked or…
KyberSwap Elastic Exploit — Tick-Boundary Precision Loss Doubles Pool Liquidity
UntaggedLoss · 2.1347 WETH + 6.365 frxETH drained (~$23K at the time); part of the ~$46M total incident
KyberSwap Elastic is a Uniswap-V3-style concentrated-liquidity AMM. Active liquidity (baseL) is adjusted as the price crosses initialized ticks by adding/subtracting tha…
LinkDao Exploit — Mis-scaled Constant-Product `K` Check in a Custom Uniswap-V2 Fork
Loss · ~$30K — 29,662.36 USDT drained from the LKD/USDT pair in a single flash swap
LinkdaoDexPair is a fork of Uniswap V2 whose swap() re-implements the constant-product (x·y ≥ k) safety check with the protocol's own fee parameters. The fork got the sc…
MahaLend Exploit — Empty-Reserve Liquidity-Index Inflation + Share-Rounding Theft
Loss · ~$20K (per the PoC's @KeyInfo). The attacker walked off with a free over-collateralized l…
MahaLend is a verbatim Aave-V3 fork. Aave's per-reserve accounting tracks a liquidityIndex (a RAY-scaled 1.0-based exchange rate from scaled aToken shares to underlying)…
MetaLend Exploit — Empty-Market Exchange-Rate Inflation via `selfdestruct` Donation
Loss · ~$4,000 — 1.9841441 WETH extracted (≈ all of the mWBTC market's lendable WBTC: 0.10999999…
MetaLend is a Compound-V2 / CREAM fork. Each market (mETH, mWBTC, …) mints an interest-bearing receipt token whose redemption value is governed by the exchange rate:
MEV Bot `0x8c2d` Exploit — Permissionless Asset-Harvester Drains a Pre-Approved Victim
Loss · 366,058.04 BUSDT (~$365K) swept from the victim MEV bot; attacker net +364,956.56 BUSDT a…
The victim — a private MEV bot at 0x8c2d… — outsourced its asset custody / sweeping to a shared "asset harvesting" contract at 0x19a2… and had pre-approved that harveste…
MEV-Bot Fleet Exploit (`0xa247…`) — Unprotected `removeAdmin()` Lets Anyone Seize and Drain 24 Bot Contracts
Loss · ~$150K — 49.63 WETH + 3.49 ETH (native) + 234,364 BUMP + assorted ERC-20 dust, drained fr…
A fleet of 24 nearly-identical "MEV-bot" contracts all delegate to one shared implementation 0xB4ba49c9…. That implementation exposes a function with selector 0xe7d25975…
OKC Exploit — Permissionless `processLPReward()` Pays Out on a Flash-Minted LP Position
Loss · ~6,268 USDT profit per run, paid out of the MinerPool's 8.36M-OKC reward treasury (≈ $6.3…
OKC ships a "hold LP, earn OKC" yield program in its MinerPool contract. The payout function processLPReward() is permissionless and computes each holder's reward from t…
Onyx Protocol Exploit — Empty-Market Exchange-Rate Inflation (Compound V2 Fork)
Loss · ~$2,000,000 — attacker ends with 1,156.93 WETH of pure profit, drained across 8 Onyx mark…
Onyx is a Compound V2 fork. A Compound V2 cToken values collateral as exchangeRate = (cash + totalBorrows − totalReserves) / totalSupply. When a market is emptied down t…
Raft Finance Exploit — Indexable-Collateral `setIndex` Inflation + `divUp` Rounding Mint
Loss · ~$3.2 M — attacker minted 6,638,934 R (the protocol's stablecoin) backed by ~150 wei of r…
Raft's collateral and debt are tracked with rebasing "indexable" tokens (ERC20Indexable). The real user-facing balance is rawBalance × storedIndex, and storedIndex is re…
SHIBAINU DAO Exploit — Underpriced ICO Sale + Lock-Bypassing `batchTransferLockToken` Pool Drain
Loss · ~$31K — attacker walked off with 101.70 WBNB (≈ $25.8K) plus residual USDT, drained from…
The SHIBAINU DAO presale (ICO.buyByBnb) sold SHIBA at a fixed amountPerStable rate of 100,000 SHIBA per $1 — i.e. $0.00001 per SHIBA. At the fork block the live SHIBA/US…
StakeStone `StoneVault` Exploit — Same-Block Deposit + `instantWithdraw` Skims Strategy-Realization Surplus
Loss · ~17.07 ETH (≈ $30K at the time) skimmed from honest StoneVault LPs
StoneVault is an ETH LST vault. It mints STONE shares on deposit and lets users redeem them with instantWithdraw. Redemptions are priced at a conservative share price (m…
Swamp Finance Exploit — Atomic `earn()` Harvest-Sandwich on `StrategyBelt_Token`
Loss · +0.548 WBNB per reproduced cycle (≈ $110 at the time). The live attack repeated the cycle…
Swamp Finance's StrategyBelt_Token is an auto-compounding yield strategy. It accounts user positions with the classic wantLockedTotal / sharesTotal share model:
TheNFTV2 Exploit — Broken `transferFrom` Access Control Lets Anyone Re-Pull Burned NFTs and Drain Their Wrapped DAO
Loss · ~$19,000 — 1.906 WETH drained from the TheDAO/WETH Uniswap-V2 pool
TheNFTV2 is an NFT that wraps one DAO token per NFT. Burning an NFT (burn()) refunds 1 DAO (here oneDao = 1e16 wei) to the caller and sends the NFT to a constant dead ad…
TheStandard.io Exploit — SmartVault `swap()` with Zero Slippage Protection Through an Attacker-Controlled Pool
Loss · ~$290K — 290,000 EUROs minted against collateral that was simultaneously drained out of t…
SmartVaultV2 lets a vault owner mint EUROs against deposited collateral, and also exposes a convenience swap() that swaps one of the vault's collateral assets for anothe…
TrustPad `LaunchpadLockableStaking` Exploit — Deposit/Withdraw Reward-Accounting Desync
Loss · ~$155K — the staking contract's TPAD reward reserve drained (final pool balance read 29,4…
LaunchpadLockableStaking is the staking/IDO-allocation pool behind the TrustPad launchpad. It exposes an "up-pool" credit path, receiveUpPool(account, amount), which pul…
WECO Staking Exploit — Reward-Debt (`offsetPoints`) Unit Mismatch Lets a Depositor Re-Claim the Whole Reward Pool
Loss · ~$18K in the live incident; in the PoC reproduction 888,001,185 WECOIN (the staking contr…
WECOStaking is a MasterChef-style staking contract. It tracks each user's "already-paid" reward checkpoint in UserInfo.offsetPoints (the classic rewardDebt). A claim pay…
XAI / CoinToken Exploit — Reflection-Token `burn()` Collapses Pool Balance via Un-touched `_rTotal`
Loss · The attacker walked off with 2562.53 WBNB of pool liquidity; net profit on the flash-loan…
CoinToken is an "RFI / reflection" token: a holder's visible balance is not stored directly. It is computed on the fly as balanceOf = _rOwned[acct] / rate, where rate =…
Astrid Protocol Exploit — `withdraw()` Trusts an Attacker-Supplied "Restaked Token"
Loss · ~$228,591 — 127.797 ETH (64.176 stETH + 39.166 rETH + 20.000 cbETH drained)
AstridProtocol lets users deposit liquid-staking tokens (stETH, rETH, cbETH) and receive a "restaked" receipt token, and later withdraw() to queue a redemption that is f…
BelugaDex Exploit — Stableswap Coverage-Ratio Manipulation via Deposit / Cross-Asset-Swap / Withdraw Looping
Loss · ~59.13 ETH extracted (≈ $175K at the time per SlowMist)
BelugaDex is a Platypus/Wombat-style single-sided stableswap. Each asset (USDT, USDC.e) has its own LP/Asset contract that tracks two scalars: cash (tokens physically he…
BH Exploit — Spot-Reserve-Priced Liquidity Manager Drained via Flash-Loan Price Manipulation
Loss · ~$1.27M — attacker walked away with 1,277,481 BUSDT (started with 0) plus 22.08M BH dust
The "Recovery" liquidity manager lets a user deposit BUSDT (selector 0x33688938) and later withdraw (selector 0x4e290832). On deposit it adds BUSDT+BH to the BUSDT/BH Pa…
DePayRouterV1 Exploit — Output-Only Balance Check + Repeated Plugin Execution Drains Router Funds
Loss · ~870.92 USDC (870,917,088 6-dec units) drained from the DePayRouterV1 contract in this tx…
DePayRouterV1.route() is a generic "swap-and-pay" router. It pulls in the input token once, runs a caller-supplied list of plugins, then checks only that the balance of…
HopeLend Exploit — Liquidity-Index Inflation + aToken Rounding-Error Drain
Loss · ~$825,000 — the entire reserves of the HopeLend hToken vaults (WETH, USDT, USDC, HOPE, st…
HopeLend is an Aave-V3 fork. In Aave-style markets, a user's deposit is recorded as a scaled balance = amount.rayDiv(liquidityIndex), and the index only ever grows as in…
Kerberus / kTAF Exploit — Compound-Fork Exchange-Rate Inflation via a Donatable, Tiny-Cash Collateral Token
Loss · ~$8.19K — 8,187.51 DAI (the entire DAI cash of the kDAI market) drained, plus 3,300 TAF r…
kTAF is a textbook Compound v2 CErc20Immutable market whose collateral exchange rate is computed live from how much underlying it currently holds:
LaEeb Exploit — Fee-on-Transfer + Auto-Liquify Pool Drain via `skim()` Recycling
Loss · ~1.81 WBNB (≈ $370 at the time) drained from the LaEeb/WBNB PancakeSwap pair
LaEeb is a "reflection / dividend" meme token whose _transfer() charges a multi-bucket fee (marketing / liquidity / LP / dead / referral) on every AMM-side transfer, acc…
Liquidator can increase a position while liquidating — AuditVault synthetic reduction
This bug report is about a vulnerability found in the Market contract of the Perennial Protocol. The vulnerability allows a malicious liquidator to liquidate a user whil…
LooksRare "Infiltration" — _killWoundedAgents kills a healed agent
1. _killWoundedAgents(roundId, ...) kills every agent in its list whose status == AgentStatus.Wounded — but it never checks woundedAt == roundId. 2. A player's agent is…
LooksRare "Infiltration" — attacker steals the grand prize by force ending the game
1. The game force-ends the instant gameInfo.activeAgents == 1 (startNewRound reverts GameOver). 2. claimGrandPrize pays the prize to whoever owns the agent parked at the…
Maestro Router 2 Exploit — Arbitrary `transferFrom` via Unvalidated Router Call
Loss · ~280 ETH across the full campaign; 14.04 WETH in the single reproduced transaction
The Maestro Router exposed a function with selector 0x9239127f that takes a token address and a raw bytes blob of calldata, and then executes that calldata against that…
maxRedeem permits leverage above the configured buffer — AuditVault synthetic reduction
A bug report has been identified in the Vault leverage calculations. The bug is caused by incorrect maxRedeem calculations with closable and LEVERAGE_BUFFER. This was fo…
MicDao Exploit — Fixed-Rate Presale Swap Arbitraged Against a Self-Manipulated AMM Pool
Loss · ~$12.26K — 12,260.25 BUSDT net profit, drained from the MicDao/BUSDT pool's real liquidity
MicDao was being sold through a presale-style helper contract (SwapContract at 0x19345233…) that hands out a fixed 10 MicDao per 1 BUSDT regardless of the live market pr…
NextGen — Permanent DoS due to non-shrinking array in unbounded loops
UntaggedparticipateToAuction only pushes bids; arrays never shrink. returnHighestBid / claimAuction iterate the full array. Enough dust bids make claim OOG → permanent auction D…
Open Dollar — incorrect calculations for surplus auction creation
Untagged1. auctionSurplus compares surplusTransferPercentage to ONE_HUNDRED_WAD (always true). 2. amountToSell uses wmul(ONE_HUNDRED_WAD - pct) → ~99× surplusAmount. 3. At 100%…
Open Dollar — missing debt check lets users start a debt auction of non-existent debt
1. auctionDebt() checks debtAuctionBidSize > _unqueuedUnauctionedDebt(debtBalance) using the current (pre-settle) debt balance, reverting only if there isn't enough. 2.…
OpenLeverage `RewardVaultDelegator` Exploit — Re-initializable Proxy → Admin Takeover → Arbitrary `delegatecall`
Loss · ~$8K — 37.137 BNB swept from the contract + the addresses that had approved it
RewardVaultDelegator is a Compound-style delegator/proxy. Its admin is supposed to be set once, by the constructor, by delegate-calling the implementation's initialize(.…
Party Protocol — single host can unfairly skip the veto period for a proposal
1. After a proposal passes its vote threshold, hosts get a chance to accept it; once ALL hosts have accepted, the veto delay is skipped and the proposal becomes immediat…
Platypus Finance (PoolSAvax) Exploit — Withdraw-While-Insolvent Coverage-Ratio Manipulation
Loss · ~$2.0M — attacker netted 23,563.75 WAVAX + 20,873.79 sAVAX ≈ 46,722 AVAX-equivalent from…
Platypus is a single-pool stableswap-style AMM. Each token in a pool is represented by an Asset contract that tracks two numbers: cash (underlying tokens actually held)…
pSeudoEth (pEth) Exploit — `skim()`-Pumped Reflection Token Drains the AMM Pool
Loss · ~1.44 WETH (≈ $2.3K at the time) — the entire WETH side of the pEth/WETH pair
pEth is a "reflection" token: on certain transfers it mints a fixed bonus directly into the recipient's balance. Critically, when tokens are transferred to the AMM pair,…
Reward claim reentrancy pays twice — AuditVault synthetic reduction
This bug report discusses a vulnerability in which malicious users can steal reward tokens through a re-entrancy attack. The vulnerability is caused by a function that u…
Stars Arena Exploit — `buyShares` Reentrancy Inflates the Price-Curve Weight
Loss · 266,102.97 AVAX (~$2.9M) drained from the Stars Arena shares contract
Stars Arena is a "friend.tech"-style social app on Avalanche: each user (a subject) has shares priced by an on-chain bonding curve. buyShares collects AVAX, splits a fee…
UniBot Router Exploit — Arbitrary External Call Drains Unlimited Approvals
Loss · 1,482.32 UNIBOT drained from 17 approving users (~$84K at the time; the campaign across m…
UniBot is a Telegram trading bot. To trade on a user's behalf, users approve(router, type(uint256).max) on the tokens they want the bot to manage, then the bot's on-chai…
Vesting claim updates index after an external call — AuditVault synthetic reduction
Issue H-3 is a vulnerability in the Vesting.sol contract that allows users to drain the contract by exploiting the claim() function. This is due to the contract executin…
Wise Lending Exploit — First-Depositor Share Inflation via `pseudoTotalPool` Donation
Loss · ~$260,000 (rescued by a whitehat; same bug, same tx pattern an attacker would have used)…
Wise Lending prices lending shares with the classic shares = amount totalShares / pseudoTotalPool formula (contracts_MainHelper.sol:55-57). The denominator pseudoTotalPo…
ZS Token Exploit — Permissionless `destory_pair_amount()` Pool-Reserve Burn
Loss · ~$14,026 — 14,026.76 BUSD-T drained from the ZS/BUSD-T PancakeSwap pair
ZS is a deflationary token that, on every sell into its PancakeSwap pair, accumulates the sold amount into a public counter Burnamount (contracts_ZS.sol:1500). The funct…
0x0 Privacy DEX (OxODex) Exploit — Forged LSAG Ring Signature + Stale `_lastWithdrawal` Pool Drain
Loss · ~$61K — ~49.85 ETH drained from the OxODex ETH pool
OxODex is a privacy mixer / "privacy DEX." Users deposit() ETH together with a public key into an anonymity ring, then later withdraw() by proving membership with an LSA…
APIG Token Exploit — Self-Transfer Balance-Doubling Bug Drains Two Pools
Loss · 59.5 ETH + ~72,113.58 BSC-USD ≈ $169K drained from two PancakeSwap pools
The APIG token's transfer() is written so that when from == to (a self-transfer), the sender's balance is credited without being debited — every call to APIG.transfer(se…
BankX / XSD Exploit — Router `swapXSDForETH()` Triggers an Un-Compensated Pool Burn
Loss · 56.96 WBNB drained from the XSD/WBNB pool (≈ $12.5K at the time)
The BankX Router.swapXSDForETH(amountOut, amountInMax) is a Uniswap-V2-style "swap exact-XSD for ETH" wrapper, except for a fatal bolt-on at the end: after performing th…
BFCToken Exploit — `lastTx` Deferred Pool-Burn Desyncs PancakeSwap Reserves
Loss · ~$38K — 179.87 WBNB drained out of the attack (≈ 440,287 BUSDT siphoned from the BFC/BUSD…
BFCToken is a "DeFi-flavoured" reflection token with a per-trade tax. On every swap into the pair it carries forward a slice of the previous trade in a state variable ca…
CEXISWAP Exploit — Unprotected `initialize()` + UUPS Arbitrary Upgrade Drain
Loss · 30,000 USDT (~$29,966) drained from the CEXISWAP proxy
CEXISWAP is an upgradeable (UUPS / ERC-1967) AccessControl token proxy that left its initialize() function callable by anyone. The deployed proxy had received 30,000 USD…
DAppSocial Exploit — `withdrawTokensWithAlt` Credits Instead of Debiting the Depositor Ledger
Loss · ~$16K — 10,335.88 USDT + 6,592.36 USDC of other depositors' funds drained from the escrow
DAppSocial is a token escrow. Users depositTokens to credit an internal balance ledger, and can withdrawTokens to pull them back. It also supports a delegated path: acco…
DEXRouter Exploit — Unprotected `functionCallWithValue` Drains the Router's Native BNB
Loss · 20 BNB (≈ $4,000 at the Sept-2023 BNB price) — the entire native-coin balance of the rout…
DEXRouter exposes a public function — functionCallWithValue(address target, bytes data, uint256 value) — that performs an arbitrary external call to a caller-chosen targ…
DittoETH — Flag can be overridden by another user
1. A flaggerId is a global, reusable slot (flagMapping[id] => address tracks who currently holds it); each ShortRecord just stores WHICH flaggerId number flags it. 2. se…
DittoETH — New orders can overwrite active orders when order id reaches 65000
1. DittoETH tracks each order side (bids/asks/shorts) as a doubly-linked list between HEAD and TAIL sentinels, PLUS a second, dual-purpose "reuse chain" of cancelled ord…
DittoETH — Owner of a bad ShortRecord can front-run flagShort calls AND liquidateSecondary
1. Every DittoETH short position (a ShortRecord) can be represented as an NFT and transferred. 2. flagShort and liquidateSecondary both require their TARGET ShortRecord…
DittoETH — Users can lose collateral when exiting a short
1. exitShort closes a short by placing a bid to buy back its debt. 2. If a user has a partially-filled short (some debt already locked into a ShortRecord, the rest still…
DittoETH — Users lose funds and market functionality breaks when market reaches 65k id
1. When a user places a limit order, the amount they commit is deducted from their escrowed virtual balance and locked into the order. 2. The normal cancel path, cancelB…
Entangle Trillion DexWrapper accepts `amountOutMin = 0` — MEV sandwich
FireBird Finance Exploit — Manipulable Protocol-Fee LP Mint Drains the WMATIC/HOPE Pool
Loss · ~3,197.67 WMATIC profit in this tx (≈ part of ~8,536 MATIC total across the campaign)
FireBird's AMM accrues a protocol fee not as an instantaneous skim, but as a running counter (collectedFee0 / collectedFee1) accumulated inside every swap() (FireBirdPai…
FloorDAO Exploit — Self-Donated Rebase Inflates the Staking `index`, Over-Paying gFLOOR Redemptions
Loss · ~40.15 WETH (~$64K at the time) — drained from the FLOOR/WETH UniswapV3 pool
FloorStaking is an OlympusDAO-V2 fork. Stakers can hold their position either as sFLOOR (a rebasing token, balance grows each epoch) or as gFLOOR (a non-rebasing "wrappe…
HCT (CoinToken) Exploit — Reflection-Token `burn()` Deflates the Pool's Reserve to 1 wei
Loss · ~$8.6K — 31.05 WBNB profit drained from the HCT/WBNB PancakeSwap pair
CoinToken (HCT) is a SafeMoon-style reflection token: every account's balance is stored as a reflected amount _rOwned[account] and the visible balance is computed on the…
Heavens Gate (HATE) Exploit — Rebase-Index Inflation via Permissionless `stake`/`unstake` Looping
Loss · ~7.85 ETH (≈ $13K at the time) — drained from the HATE/WETH Uniswap-V2 pair across two tr…
HATEStaking is a fork of the OlympusDAO staking system. sHATE is a rebasing share token: each account stores an internal gon balance, and the displayed balance is gons /…
JumpFarm Exploit — Single-Transaction Rebase Inflation in OlympusDAO-style Staking
Loss · ~2.406 WETH (≈ $2.4K at the time) drained from the JUMP/WETH Uniswap-V2 pool via free-min…
Staking is an OlympusDAO-style (Olympus/Wonderland v1) staking contract: you deposit JUMP, receive sJUMP (a rebasing receipt token) 1:1, and the receipt's balance grows…
Lumin — Collateral double-spend post liquidation is possible
1. AssetManager tracks each user's collateral in a UserDeposit{depositAmount, lockedAmount} struct. Withdrawals are gated on the free balance: depositAmount - lockedAmou…
Lumin — Disabled lender's loan configuration can be used by a borrower
1. A LoanConfig has an enabled flag, true by default, that a lender can flip to false via updateLoanConfigEnabledStatus — her only lever to stop further loans from being…
MuseumOfMahomes — last NFT of the supply can't be minted (off-by-one `>=`)
1. mint() guards the supply with if (nextId + amount >= MAX_SUPPLY) revert ExceedsMaxSupply();. 2. Valid tokenIds are 0 .. MAX_SUPPLY-1 (that is MAX_SUPPLY tokens), and…
Nouns Builder — when reservedUntilTokenId > 100, first founder loses 1% NFT
1. _addFounders schedules a founder's NFT allocation slots by seeding a cursor: uint256 baseTokenId = reservedUntilTokenId;. 2. Every REAL ERC-721 token id that will eve…
Quantum Wealth Network (QWA) Exploit — Re-entrant `rebase()` Reward Harvest via stake/unstake Looping
Loss · ~0.578 WETH (~$900 at the time) extracted from the QWA staking system in a single transac…
QWAStaking is an Olympus-style staking system. Staking QWA gives you sQWA 1:1; the sQWA token rebases (mints supply to existing holders) every epoch, so when you later u…
Split (Kub) Exploit — Self-Doubling Balance via Manipulable On-Chain "Token Price" Oracle
Loss · ~$22.2K — attacker netted 22,049.48 BUSDT + 126.38 KUB (≈ $22.2K) after repaying all flas…
Split is a "reflection"-style deflationary token. On every token transfer its _beforeTokenTransfer hook calls setSplit() (Split.sol:1231-1237). When an internal price re…
Unicly PointFarm Exploit — ERC1155 Reentrancy Inflates Reward Points to Steal a LootRealms NFT
Loss · 1 NFT — LootRealms #4689 (a "Realm" NFT, redeemed from the Unicly shop without enough poi…
PointFarm is a SushiSwap MasterChef fork (its own header says "Copied from … MasterChef.sol — Modified by 0xLeia") that pays farming rewards as an ERC1155 "points" token…
Venus Prime — stale staking timestamp permits a free revocable Prime claim
stakedAt determines whether an account has waited long enough to claim a revocable Prime token. The irrevocable issue branch mints the token but does not clear that time…
Balancer Boosted Pools Exploit — Linear-Pool `getRate()` Inflation via BPT Supply Drain + Precision Loss
Loss · ~$2.1M total across all affected Balancer V2 boosted pools (this PoC reproduces the bb-a-…
A Balancer V2 Linear Pool (bb-a-USDC) exposes getRate(), which is the on-chain "share price" of its BPT measured in underlying units. That rate is getRate() = (nominalMa…
BTC20 / 24Pixels Presale Exploit — Spot-AMM Price Oracle Manipulation in `buyWithEthDynamic()`
Loss · ~18 ETH reported on-chain (SlowMist); the isolated single-iteration PoC nets 5.68 WETH in…
The 24Pixels/BTC20 dynamic presale lets anyone buy a fixed remaining token allotment via buyWithEthDynamic(tokenAmount). It computes the ETH price for that allotment by…
Canto (veRWA) — an integer underflow can permanently DoS a gauge in `GaugeController`
1. Users vote their voting power onto a gauge. Each vote schedules a future exit — when the voter's lock ends, changes_weight[gauge][lockEnd] records how much slope shou…
Canto (veRWA) — removing a gauge permanently strands a voter's voting power
1. A voter commits 100% (10,000 bps) of their voting power to gauge1 via vote_for_gauge_weights(gauge1, 10000). 2. Governance later calls remove_gauge(gauge1) — for any…
Canto (veRWA) — undelegating back to yourself can force a 5-year lock extension
1. Bob locks CANTO for the (fixed) 5-year duration and, by default, self-delegates. 2. Bob delegates his voting power to Dave, whose lock happens to unlock later than Bo…
Canto (veRWA) — unguarded `checkpoint_lender`/`checkpoint_market` let anyone grief a lender's reward to 0
1. A lender deposits cNote into a whitelisted lending market. sync_ledger records the deposit and tracks the epoch it was last updated at. 2. checkpoint_lender(market, l…
Curve `UnderlyingBurner.execute()` — Zero-Slippage Sandwich on the 3pool
Loss · ~$36,700 — 36,700.27 USDT extracted from the Curve 3pool by sandwiching the burner
Curve's UnderlyingBurner is a fee-processing contract: it accumulates DAI/USDC/USDT (the fees the protocol skims), then anyone can call its public execute() function to…
EAC Exploit — Permissionless `_swapUForToken()` Drains the Fund Contract into a Thin Pool
Loss · ≈ 6,377 USDT (~29 BNB) profit to the attacker, sourced from 14,300 USDT force-spent out o…
The EAC project deployed a "fund" contract (reachable through proxy 0xa08a40…) exposing a public, unauthenticated function _swapUForToken(uint256 amountIn) (selector 0xe…
EarningFarm (ENF) Exploit — Withdraw Reentrancy via ETH-Push-Before-Burn in `EFVault`
Loss · ~$286K — the entire ETHLeverage strategy was drained (≈ 320.6 ETH of totalAssets at the f…
EFVault.withdraw() (contracts_core_Vault.sol:122-145) pays the user out by calling IController(controller).withdraw(assets, receiver), which forwards the strategy's rede…
EHIVE Exploit — `stake()` Updates `staked` Before Computing `earned`, Inflating Rewards
Loss · ~$15K — 9.3258 WETH net profit drained from the EHIVE/WETH pool
EHIVE is a token with a built-in 50%-APR staking program. The stake() function has a write-ordering bug (EHIVE.sol:950-956): when an address that is already registered a…
Exactly Protocol Exploit — `DebtManager` Permit-Spoofed `_msgSender` Lets Anyone Act On Behalf Of Any Account
Loss · ~$7.3M total across all Exactly markets (Optimism). This PoC reproduces only the exaUSDC…
DebtManager is a periphery helper that performs leverage / deleverage / roll operations on behalf of an account identified by an internal _msgSender variable. Several en…
GSS Exploit — Fee-on-Transfer / Reflection Token Drained via Cross-Pool `skim()`
Loss · ~$24,883 — 24,883.45 USDT extracted (flash-loaned 30,000 USDT, repaid in full, net profit)
GSS is a "reflection / auto-liquidity / dividend" BEP-20 token. Its _transfer override (GSS.sol:785-810) intercepts every transfer that touches a registered Pancake pair…
LeetSwap V2 Exploit — Public `_transferFeesSupportingTaxTokens()` Drains the Pair's Reserves
Loss · ~$630,000 — across all LeetSwap V2 pairs; this PoC drains 120.18 WETH from the WETH/axlUS…
LeetSwapV2Pair (a Solidly/Velodrome-style AMM fork) splits trading fees out of the pool by transferring the fee amount to a separate fees contract. The helper that perfo…
Livepeer — By delegating to a non-transcoder, a delegator can reduce someone else's vote tally
Untagged1. Non-transcoder Alice votes For with 100; Carol For 5000 → For=5100.\n2. Bob delegates 1000 to Alice, votes Against.\n3. Override subtracts 1000 from For without Alice…
Livepeer — Underflow in updateTranscoderWithFees can cause corrupted data and loss of winning tickets
Untagged1. treasuryRewardCutRate stored as PreciseMathUtils % (1e27).\n2. updateTranscoderWithFees uses MathUtils.percOf (1e6).\n3. 10% cut (1e26) → treasuryRewards >> rewards →…
Neutra Finance Exploit — `Convert.getAmountOut()` Prices LP by a Spot-Manipulable Reserve
Loss · ~$48K — attacker net +23.57 WETH intra-transaction (flash-loan funded, zero capital)
Convert is Neutra Finance's LP-migration contract. A user hands it old WETH/NEU LP tokens and it pays back the equivalent number of new NEU1/WETH LP tokens from a treasu…
SVT Exploit — Broken AMM Pricing Round-Trip Drain (flash-loan funded)
Loss · ≈ 397,782 BUSD profit to the attacker, drained from the SVT/BUSD pool's BUSD reserve
The SVT pool at 0x2120… is a custom AMM exposing buy(uint256 busdAmount) and sell(uint256 svtAmount). Its pricing does not preserve a constant product — buying SVT is ch…
SYMMIO `liquidatePartyA` accepts a replayable, nonce-free Muon liquidation signature
Uwerx (WERX) Exploit — Burn-on-Transfer-to-Pool + `skim()` Reserve Collapse
Loss · 174.79 WETH profit (the pool's entire ~174.79 WETH of honest liquidity; ~$320K at the tim…
Uwerx is a standard OpenZeppelin ERC20 with one bolted-on "feature": inside _transfer, whenever the recipient equals uniswapPoolAddress, it taxes the transfer 97% / 2% /…
Zunami UZD Exploit — Spot-Price `totalHoldings()` Inflation via SDT Donation
Loss · ~$2.1M — 1,152.91 WETH + 1,275.24 USDT extracted by the attacker (≈ $2.1M at the time)
UZD is a rebasing stablecoin whose per-share price (lpPrice) is computed from the Zunami protocol's total USD holdings divided by supply. One of the underlying yield str…
[H-01] Buffer Finance v2.5 — payments for coupons to the Booster are irretrievable
ApeDAO (APE2) Exploit — Permissionless `goDead()` Pool-Reserve Burn + `skim()` Tax Pump
Loss · ~7,522.88 BUSDT (~$7.5K) drained from the APEDAO/BUSDT PancakeSwap pair
APEDAO is a fee-on-transfer "dividend" token. Two design flaws compose into a critical bug:
Arcadia Finance Exploit — Reentrant Self-Liquidation Drains the Lending Pools
Loss · ~$334K recovered at this fork block (148.22 WETH + 59,527 USDC); the live incident totall…
Arcadia's Vault is an on-chain margin account. To support leveraged DeFi actions, the LendingPool mints debt to a vault, ships the borrowed funds + the vault's collatera…
AzukiDAO (Bean) Exploit — Signature-Replay Mint via Unenforced `signatureClaimed` Guard
Loss · ~$69,000 — 6,250,000 BEAN minted to the attacker (200 × 31,250 BEAN)
Bean.claim() lets an NFT holder redeem an off-chain-signed allowance of BEAN tokens. The signature is checked with a sound OpenZeppelin ECDSA.recover against the trusted…
Bamboo AI Exploit — `updatePool()` Permissionless Pool-Reserve Siphon + `skim`/`sync` Drain
Loss · ~226 WBNB extracted by the PoC (≈ 226.13 WBNB); the live incident is reported as ~200 BNB
BambooAI is a fee-on-transfer "AI" memecoin. Its _transfer invokes a private helper updatePool(amount) on every non-pair (sell-side) transfer once trading has started (B…
Bao Finance Exploit — CErc20 Exchange-Rate Inflation via Direct Underlying Donation
Loss · ~$46,000 — attacker walked away with 23.52 WETH of net profit after repaying a flashloan
bdbSTBL is a Bao Finance lending market built on a Compound v2 / CErc20 fork. Its share price (exchangeRate) is computed live as
BNO Exploit — `emergencyWithdraw()` Resets Stake but Leaves Reward Accounting Intact, Draining the Pool
Loss · ~$505K — 763,070 BNO extracted from the staking pool (net, after flash-loan repayment)
Pool is a yield farm where users pledge() BNO and (optionally) stakeNft() to receive a reward "weight" boost. Rewards are paid in the same token that is staked — pledgeA…
Buffer `BufferBinaryPool.send()` permanently locks LP funds on an early exercise
Buffer `closeAnytime` never ties the user's close signature to the pricing timestamp
UntaggedBuffer `closeAnytime` never validates the closing timestamp against the current time
UntaggedBuffer market direction is chosen at close, guaranteeing a winning trade
Carson Token Exploit — Thin-Reserve Price Skew + Fee-on-Transfer Drain via a Custom Pair
Loss · ~$100,677 — 100,677.05 BUSDT of net profit, drained out of the Carson/BUSDT pair
Carson is a fee-on-transfer ("reflection") token: every transfer skims a tax (≈7% on the exploited path) and re-routes it to reward / dead / marketing sinks. It is paire…
Civfund (0xf485) Exploit — Forged Uniswap-V3 `mint` Callback Drains User Approvals
Loss · ~$165K — token approvals drained from 31 victim accounts (USDT, USDC, SHIB, BONE, WOOF, L…
Civfund's router contract is a Uniswap-V3 "minting" wrapper. When it adds liquidity on behalf of a user it calls pool.mint(...); the genuine pool then re-enters the rout…
CIVNFT / CivTrade Exploit — Missing Access Control + Attacker-Controlled Mint Callback Drains Approved Allowances
Loss · ~$180K — attacker drained 89,789.15 CIV (the victim's entire remaining balance) from a si…
CIVNFT is the position-manager/NFT contract behind CivTrade, a limited-range-order product built on Uniswap V3. To open a position it calls into a Uniswap V3 pool: it re…
Coinbase/Base FeeVault — `totalProcessed` inflated without sending funds (unchecked `SafeCall.send`)
1. FeeVault.withdraw() does totalProcessed += value before attempting the outbound transfer. 2. It transfers via SafeCall.send(RECIPIENT, gasleft(), value), which perfor…
Conic Finance (crvUSD Omnipool) Exploit — Curve Pool Imbalance Manipulation of LP Valuation
Loss · ~$934K total across Conic Omnipools; this PoC reproduces the crvUSD Omnipool leg, attacke…
ConicPoolV2 is a Curve "Omnipool": users deposit a single underlying (here crvUSD), the pool spreads that liquidity across several underlying Curve pools (crvUSD/USDT, c…
Conic Finance (ETH Omnipool) — Curve LP Oracle Manipulation via Spot-Reserve Pricing
UntaggedLoss · ~$3.26M — net 1,724.17 ETH extracted by the attacker (≈ $1,886.87/ETH at the fork-block C…
Conic's ETH Omnipool mints/redeems its LP token (cncETH) at an exchange rate derived from the USD value of the Curve LP positions it holds (ConicEthPool._exchangeRate, _…
Conic Finance ETH Omnipool Exploit — Curve Read-Only Reentrancy Oracle Inflation
Loss · ~$3.25M — attacker ends with 1,724.21 WETH of profit (started with 0 capital, all flash-l…
ConicEthPool prices its Curve/Convex LP holdings through CurveLPOracleV2, a balance-based oracle that values a Curve LP token as (sum of pool coin balances × spot prices…
Curve `crv/ETH` Pool Drain — Vyper 0.3.0 Broken `@nonreentrant` Lock (Read-Only/Cross-Function Reentrancy)
UntaggedLoss · ~7,929.44 WETH extracted in the reproduced single-transaction PoC. The wider July-30-2023…
The Curve crv/ETH pool is a two-coin crypto-swap pool written in Vyper 0.3.0. Every state-changing entry point (exchange, add_liquidity, remove_liquidity, remove_liquidi…
Curve Finance pETH/ETH Pool — Vyper `@nonreentrant` Compiler Bug Read-Only/Cross-Function Reentrancy
UntaggedLoss · 6,107.41 WETH net profit drained from the pETH/ETH pool (~$11.4M of pool TVL at the time)…
The pETH/ETH pool is a Curve StableSwap written in Vyper 0.2.15. Every state-mutating entry point — add_liquidity, exchange, remove_liquidity, … — carries a @nonreentran…
FFIST (FIRE FIST) Exploit — Attacker-Controlled `_airdrop()` Overwrites the AMM Pool's Token Balance to 1 wei
Loss · ~$110K — 228.30 WBNB drained from the FFIST/USDT PancakeSwap pool (≈$110K at the time)
FFIST is a fee-on-transfer token with a gimmick "airdrop" feature: on every non-whitelisted transfer, _airdrop() derives 4 pseudo-random addresses from a seed and hard-w…
GYM Network Exploit — `GymRouter` Pulls Swap Input From the *Recipient* Instead of the *Caller*
Loss · +117,193.51 GYMNET netted by the attacker (≈ the victims' drained GYMNET, repackaged as t…
The deployed GymRouter's swap…SupportingFeeOnTransferTokens family of functions pulled the input tokens from the to address (the swap recipient) rather than from msg.sen…
Libertify (LibertiVault) Exploit — Deposit Reentrancy via 1inch Swap Callback Inflates Share Mint
Loss · ~$452K — drained from the WETH/USDT LibertiVault (attacker netted 123.84 WETH + 56,234 US…
LibertiVault.deposit() is a vault-share function whose _deposit() internal routine makes an external call to the 1inch V4 aggregation router in the middle of the share-m…
LUSD (LAYER3) Exploit — Spot-Price Oracle Manipulation via `Loan.supply()`
Loss · ~$9.46K this tx — 9,464.72 USDT net (SlowMist totals the campaign at ~$16K across the att…
Loan.supply() decides how much LUSD to mint for a supplied token by asking the PancakeSwap router how much USDT that token is worth, right now, using router.getAmountsOu…
Minto Finance Exploit — Free BTCMT Minting via Unvalidated `paymentToken` in `ReferralCrowdsale.buyTokens()`
Loss · ~$9.68K — 14,724.1 BTCMT drained from the crowdsale, swapped to 9,682.2 BUSD/USDT
ReferralCrowdsale sells BTCMT for stablecoins. The buyer passes a paymentToken address and a usdtAmount. The crowdsale computes how much BTCMT that buys (getPrice), send…
NewFi / StakedV3 Exploit — Flash-Loan Price Manipulation of an Unprotected Internal V3 Swap
Loss · ~$31K — 30,473.19 BUSD net profit to the attacker
StakedV3 is a "single-token deposit, auto-Farm" wrapper around a PancakeSwap V3 concentrated-liquidity position. When a user calls Invest(...), the contract reads the li…
Palmswap Exploit — PLP Share Inflation via Permissionless `buyUSDP()` AUM Manipulation
Loss · ~$901,456 — 901,456.59 BUSDT net profit drained in a single transaction
Palmswap is a GMX fork on BSC. Its PLP liquidity token is priced off the Vault's Assets-Under-Management (AUM), and AUM is dominated by the Vault's poolAmount (PlpManage…
Platypus Finance (2nd hack) — Coverage-Ratio Arbitrage via `withdrawFromOtherAsset`
Loss · ~$51K (one of several attack txs); this PoC profits 4,472.378061 USDC in a single flash-l…
Platypus is a single-sided stableswap. Each token has an Asset LP contract that tracks two numbers: cash (underlying token actually held) and liability (what depositors…
Rodeo Finance Exploit — TWAP Oracle Manipulation of the unshETH LP Price
Loss · ~472 ETH (~$888K) across the attack campaign; this PoC's final transaction nets 144.22 WE…
Rodeo Finance let users borrow USDC against a leveraged unshETH LP strategy. The collateral value (and therefore the position's health factor) was priced by an OracleTWA…
Sablier / PRBProxy — Owner can be temporarily changed within proxy calls
Untagged1. execute DELEGATECALLs a target and only checks that owner is unchanged after return. 2. The target overwrites storage slot 0 (owner) mid-call to a colluding contract.…
Sablier / PRBProxy — Plugins can be maliciously overridden by colliding signatures
Untagged1. Plugins are installed by mapping each selector from methodList() → plugin address. 2. There is no check that the selector is free; a later install overwrites the earl…
SUT Token Sale Exploit — Fixed-Price Inventory Sold Far Below Market
Loss · ~$8K USD — 32.99 WBNB of risk-free arbitrage profit
SUTTokenSale is a primitive "ICO" contract that sells its SUT inventory at a single, admin-set, hard-coded tokenPrice (SUTTokenSale.sol:130, :145-148). At the time of th…
Tapioca DAO — AaveStrategy rewards locked as unredeemable stkAAVE
Untagged1. AAVE incentivesController stakes claimed rewards into stkAAVE immediately. 2. compound() claims incentives but never calls redeem. 3. Strategy holds stkAAVE with zero…
Tapioca DAO — AaveStrategy setMultiSwapper bricks compound
Untagged1. Constructor approves the initial multiSwapper for rewardToken. 2. setMultiSwapper only stores the new address. 3. New swapper has zero allowance → compound transferFr…
Tapioca DAO — BalancerStrategy _withdraw scales WETH as BPT
Untagged1. _withdraw converts desired WETH → BPT-like figure via getRate. 2. _vaultWithdraw encodes type-2 exact-tokens-out with that figure as minAmountsOut. 3. Vault pays only…
Tapioca DAO — FakeBigBang steals Singularity assets via unwhitelisted Magnetar repay
UntaggedFakeBigBang steals Singularity assets via unwhitelisted Magnetar repay. Harm demonstrated: Victim Singularity assets drained to attacker via FakeBigBang YieldBox allowan…
Tapioca DAO — GlpStrategy currentBalance ignores unclaimed rewards
Untagged1. YieldBox prices shares from strategy.currentBalance(). 2. _currentBalance omits unclaimed rewards. 3. Deposit → harvest → withdraw extracts older depositors' rewards.
Tapioca DAO — Magnetar has no approval checking (position drain)
Untagged1. Users approve Magnetar on YieldBox so helpers can manage positions. 2. withdrawToChain(from=victim, receiver=attacker) has no operator check. 3. YieldBox only sees Ma…
Tapioca DAO — Market solvency multiplies share before toAmount
Untagged1. Solvency multiplies userCollateralShare by rate factors before yieldBox.toAmount. 2. Dust shares that convert to 0 amount inflate into non-zero collateral value. 3. U…
Tapioca DAO — repay allowance checked on part, pulls elastic
Untagged1. approveBorrow documents a maximum spendable amount. 2. repay checks allowance against debt part. 3. _repay converts part→elastic and withdraws amount > part after int…
Tapioca DAO — steal oTAP contents via Magnetar exit/unlock
Untagged1. Victim approves Magnetar for oTAP so they can exit via the helper. 2. Attacker exits victim oTAP with a fake unlock target (no-op). 3. Attacker unlocks real tOLP with…
USDTStakingContract28 Exploit — Permissionless `tokenAllowAll()` Self-Approval Drain
Loss · ~$20,999 — 20,999.916289 USDT drained (the staking contract's entire USDT balance)
USDTStakingContract28 is a USDT staking/yield contract that holds users' deposited USDT. It exposes a public helper, tokenAllowAll(address asset, address allowee) (USDTS…
Utopia Exploit — `_airdrop()` Overwrites the Pool's Token Balance to 1, Collapsing the AMM Reserve
Loss · ~$119K — 492.08 WBNB drained from the Utopia/WBNB PancakeSwap pair (attacker started with…
Utopia is a fee-on-transfer "dividend" token. On every taxed buy/sell it runs a marketing gimmick called _airdrop() (Utopia.sol:327-342) that mints 1 wei of Utopia to a…
WGPT (Wrapped GPT) Exploit — Self-Inflicted `removeLiquidity` on Every Sell Drains the Pool
Loss · ~$80K — attacker walked away with 76,944.26 BUSD-T of profit (from a ~$0 starting balance…
AiWGPTToken is a "deflationary" token whose transferFrom hook runs a self-managed burn every time tokens are sold into a registered pair. Instead of merely destroying to…
Abracadabra / MIM `ZeroXStargateLPSwapper` Exploit — Arbitrary-Calldata Approval Drain
Loss · ~$17K — 17,991.96 MIM stolen from the swapper's residual USDT balance
ZeroXStargateLPSwapper is one of Abracadabra/MIM's "swapper" helper contracts. It liquidates a Stargate-LP collateral position by (1) redeeming the LP for its underlying…
ARA Exploit — Permissionless "Swap-on-Behalf" Helper Drains a Pre-Approved Address via Pool Price Manipulation
Loss · ~$125K — attacker netted 124,914.92 BUSDT (the pre-approved address was whipsawed for ~$4…
The ARA project deployed a "swap helper" contract, 0x7BA5dd9Bb357aFa2231446198c75baC17CEfCda9, exposing a function swapExactInputSingle(uint256 amount, uint256 minOut, a…
BabyDogeCoin Exploit — Sandwiching the Token's Slippage-Free `swapAndLiquify`
Loss · ~$100K — net 441.9 WBNB retained by the attacker after repaying all loans
BabyDogeCoin is an old-style "reflection + auto-liquify" token. On large transfers it accumulates a liquidity fee in its own balance, and once that balance reaches numTo…
Beanstalk Wells — `removeLiquidity` is wrong for generalized (non-linear) Well functions
1. addLiquidity mints LP using the Well function (calcLpTokenSupply), so the invariant holds on the way in. 2. removeLiquidity does not invert the Well function — it pay…
Beanstalk Wells — protocol invariant can be broken, bricking a valid withdrawal
1. Well.removeLiquidity pays out proportionally: lpAmountIn * reserves[i] / lpTokenSupply. That is correct only if the Well function is linear — but ConstantProduct2 (b_…
Beanstalk Wells — read-only reentrancy in `Well.removeLiquidity`
1. Well.removeLiquidity burns the caller's LP first, then transfers each underlying token out, and only after the loop calls _setReserves. 2. If one token has a transfer…
Biswap V3Migrator Exploit — Arbitrary `recipient` LP Theft via Unauthorized `migrate()`
Loss · ~$72K — the victim's entire BTCB/BSC-USD V2 LP position (≈ 28.149 BTCB + 53,553.74 BSC-US…
Biswap's V3Migrator is a periphery helper meant to let a user move their own Uniswap-V2-style LP into a Biswap V3 concentrated-liquidity position. Its migrate() function…
Bunny Protocol (BUNN) Exploit — Reflection `deliver()` Inflates Pair Balance, Spoofing the AMM K-Check
Loss · 52 WBNB drained from the BUNN/WBNB PancakeSwap pair (≈ $12–13K at the June-2023 BNB price)
BunnyProtocol is a fork of the RFI / SafeMoon "reflection" token design. Holder balances are stored not as raw amounts but as reflection units _rOwned, and the visible b…
Cellframe Network Exploit — Manipulated Reserve Ratio in `LpMigration.migrate()`
Loss · ~$76,000 — attacker WBNB balance went 0.1 → 245.52 WBNB (net +245.42 WBNB)
LpMigration was a one-shot helper that lets a holder of the old CELL/WBNB LP token swap it for the new CELL/WBNB LP token. For each migrated LP position it:
CFC Exploit — Self-Burning `sync()` + `skim()` Reserve Drain
Loss · +6,124.40 BEP20USDT net profit this transaction (PoC). SlowMist reported ~$16K total acro…
CFC is a "tax + dividend" BEP20 whose _transfer runs an internal sync() helper on every sell (any transfer where to == uniswapV2Pair). That helper directly mutates the p…
Compounder Finance Exploit — Inflatable Share Price via Curve `get_virtual_price()` Manipulation
Loss · ~$27.17M (per the @KeyInfo header in the PoC). The extracted PoC reproduces a representat…
Compounder Finance is a yield aggregator. Its cVault_DAI mints/redeems share tokens (cDAI) priced off balance(), which equals the vault's own DAI plus the value reported…
Contract `0x7657…` Exploit — Permissionless `transferFrom`-Drain of Standing Approvals
Loss · 20,000.01 USDT drained from the victim
The contract at 0x7657… holds a public function with selector 0x0a8fe064. The function takes five ABI words — (address recipient, address from, uint256 _, uint256 amount…
DDCoin (DD) Marketplace Exploit — Self-Granted Allowance Lets the Seller Drain the Escrow Twice
Loss · ~$300K reported; this reproduction nets 126,409.24 BUSDT to the attacker in one transacti…
Marketplace.sellItem() pays a seller in two pieces of code that should be mutually exclusive but are not:
Dhedge L2Comptroller — user can receive too few tokens when unpaused (cross-domain replay)
1. When MTA is burnt on L1, a cross-domain message eventually calls L2Comptroller.buyBackFromL1(l1Depositor, receiver, totalAmountBurntOnL1) on L2, crediting the deposit…
Midas Capital Exploit — cToken Exchange-Rate Inflation via Donation Into a Near-Empty Market
Loss · ~$600K — attacker walked off with 590,964 ANKR + 116 ankrBNB plus borrowed HAY/ankrBNB, l…
Midas Capital is a Fuse/Compound-fork isolated-lending market. Several markets used ERC4626-vault-wrapped Thena LP tokens as the cToken underlying.
MyAi (CoinToken) Exploit — `MultiSender` Lets Anyone Spend a Victim's Pre-Approved Allowance Into a Hyper-Thin Pool
Loss · ~10.77 WBNB (≈ 10 BNB) drained from the MyAi/WBNB PancakeSwap pair
MultiSender.batchTokenTransfer() (MultiSender.sol:297-324) is a public, unauthenticated airdrop helper. It takes an arbitrary _from address and does IERC20(token).transf…
NST Swap Exploit — Dangling `approve()` lets the buyer drain the swap contract's USDT reserves
Loss · 29,195.083207 USDT (~$29,195) stolen from the swap contract
Milktech's NST swap contract is a simple fixed-price exchange between USDT (6 decimals) and the company token NST (4 decimals), holding a USDT float to pay out sellers.
Pawnfi `ApeStaking` Exploit — Unrestricted `collectRate` + Vault-Funded Staking Drains the P-BAYC ApeCoin Reserve
Loss · ~$820K — drained the ApeCoin (APE) reserve held by Pawnfi's P-BAYC vault, plus ~102.3 ETH…
Pawnfi's ApeStaking lets a user deposit a "P-BAYC" wrapped NFT, have the protocol stake the underlying BAYC into Yuga's ApeCoinStaking, and later withdraw the staked Ape…
SellToken `miner` Exploit — Spot-Price Reward Oracle Drained via Flash-Loaned Liquidity
Loss · ~123.30 WBNB net profit drained from the miner contract's SELLC stockpile (≈ US$30–35K at…
miner is a yield/"mining" contract that lets a user register a deposit (setBNB) and then, once per day, claim a SELLC reward via sendMiner() (miner.sol:308-329). The rew…
SHIDO Exploit — `ShidoLock` Migration Mint With No Eligibility Check
Loss · ~977.07 WBNB net (≈ $230K at the June-2023 BNB price) drained from the SHIDO-V2/WBNB pool
ShidoLock is the contract that migrates holders of the old SHIDOINU (V1, 9 decimals) token to the new SHIDO (V2, 18 decimals) token. Migration is two steps:
SHIDO Migration Exploit — `claimTokens()` Blind `× 10⁹` Decimal Scaling Drains the Reward Wallet
UntaggedLoss · ~976.98 WBNB (≈ $283K at the time) extracted from the SHIDO migration reward wallet, mone…
ShidoLock is the migration bridge from SHIDO V1 (SHIDOInu, 9 decimals) to SHIDO V2 (StandardToken, 18 decimals). A user calls lockTokens() to deposit their V1 balance, t…
STRAC Exploit — Permissionless Token-Drainer in a Helper Contract (Spoofable `transferFrom`)
Loss · 12.1629 ETH (Binance-pegged ETH, 0x2170…F8) — ≈ $13 ETH per the PoC header, ~$22K at the…
A helper contract at 0x1F90…E7A513 held a stash of 130.97 STRAC and exposed a public, unauthenticated function (selector 0x4a75084c) whose behaviour, reconstructed verba…
Sturdy Finance Exploit — Balancer Read-Only Reentrancy Inflates LP-Token Collateral Price
Loss · ~$800K (≈442 ETH across the live multi-iteration attack). This single-pass PoC nets 217.7…
Sturdy is an Aave-v2 fork that accepts Balancer/Curve LP tokens as collateral. It prices the B-stETH-STABLE BPT through a custom Chainlink-shaped source (0x232a8829…) wh…
Sudoswap `VeryFastRouter` — malicious pair re-enters `swap` to drain the original caller's ETH
1. VeryFastRouter.swap is the batch sell/buy entry point. It is not nonReentrant and never checks that a supplied order.pair is a real factory pair. 2. A user is tricked…
Sudoswap LSSVMRouter — specified `minOutput` remains locked in the router
1. swapNFTsForSpecificNFTsThroughETH sells the user's NFTs for ETH, then uses that ETH (plus msg.value) to buy the specific NFTs the user wants. 2. For the ETH→NFT half…
Themis Protocol Exploit — Manipulable Balancer-LP (BPT) Price Oracle Enables Over-Borrowing
Loss · ~$370,000 (≈ 94.32 WETH + 130,471.92 USDC + 58,824.33 USDT walked off-chain)
Themis is an Aave V3 fork on Arbitrum that accepted the Balancer wstETH/WETH gauge LP token as collateral. To value that LP token it called an oracle at 0x17df2B52f5…, w…
Threshold USD — mintList early-return lets depositors run away with collateral
Untagged1. When BorrowerOperations is removed from thUSD.mintList, adjustment guards early-return. 2. ICR / recovery-mode checks never run for withdrawColl. 3. Alice withdraws n…
UN Token Exploit — Fee-on-`swap`-out + `skim()` Reserve Drain
Loss · ~$13,412 — 13,412.36 BUSD profit drained from the UN/BUSD PancakeSwap pair
UN is a fee-on-transfer token whose _transfer override applies its tax to the wrong account on the buy side. When someone buys UN out of the registered swapPair, the fro…
Unverified Staking Contract — `claim()` Double-Spend of Deposited BUSD
Loss · ~$5,955 — 5,955.466788 BUSD drained from the staking contract
A small BUSD staking/farm contract at 0xAC899… lets a user deposit(pid, amount) and later claim(pid, amount). The trace shows that claim() returns the staked principal t…
Viral Inu (VINU) Exploit — Permissionless `addLiquidityETH()` Drains Pool's Own Token Reserve
Loss · ~$6,000 — 3.2565 WETH drained from the VINU/WETH Uniswap V2 pair (against ~0.1 ETH outlay)
VINU is a fake "Viral Inu" memecoin engineered as a honeypot/backdoor. Two design choices combine into a public, free pool-drain:
Vortex DEPUSDT / LEVUSDC Exploit — Public `approveToken()` → Arbitrary Reserve Drain
Loss · ~$106K — 69,961.509697 USDT (from the DEPUSDT market) + 36,142.023929 USDC (from the LEVU…
The Vortex lending markets (DepErc20 for USDT, LevErc20 for USDC) inherit a Curve-swap helper CurveSwap that exposes:
Ajna Grants — Delegation rewards are not counted toward granting fund
1. Each quarter a Global Budget Constraint (GBC = 3% of the treasury) is reserved as fundsAvailable. It splits 90% for proposals and 10% for voter (delegate) rewards. 2.…
Ajna Protocol — Position NFT can be spammed with insignificant positions by anyone until rewards DoS
1. PositionManager.memorializePositions is external and — unlike burn(), moveLiquidity() and reedemPositions(), which are all gated by mayInteract (owner-or-approved) —…
Ajna Protocol — PositionManager's `moveLiquidity` freezes LP via wrong deposit time
Untagged1. moveLiquidity copies fromPosition.depositTime onto toPosition. 2. Destination bucket may have bankruptcyTime > from.depositTime. 3. Pool-side LenderActions renews dep…
Ajna Protocol — PositionManager's `moveLiquidity` freezes residual LP on partial moves
1. moveLiquidity removes fromIndex from positionIndexes before calling pool.moveQuoteToken. 2. moveQuoteToken can move only part of the requested quote when deposit is t…
BabyDoge FarmZAP Exploit — Untrusted `farm` Callback Lets Anyone Drain Swapped Tokens
Loss · ~$7.5M total across repeated runs (per DeFiHackLabs header). This single reproduced trans…
FarmZAP.buyTokensAndDepositOnBehalf(IFarm farm, …) (contracts_FarmZap.sol:184-223) is meant to: take your input token, swap it to a farm's stake token through the BabyDo…
Bitpaidio (BTP) Staking Exploit — Stale-Lock Reinvest Bug Enables Instant Flash-Loaned Staking ROI
Loss · ~$30K (PoC nets 10,417.70 BTP of free ROI per round; the live drain repeated to empty the…
Bitpaidio's Staking contract offers fixed-term staking (6 / 9 / 12-month plans) that pays a flat ROI (5% / 10% / 20%) when the lock expires. To support topping up an exi…
CS Token Exploit — Stale Global `sellAmount` Drives an Attacker-Triggerable Pool Burn
Loss · ~684,175 BSC-USD (≈ $684K) extracted in a single transaction
CS is a fee-on-transfer token with a "deflation" feature that burns CS directly out of its own liquidity pool. The amount it burns is read from a global state variable s…
DEI Stablecoin Exploit — `burnFrom()` Grants the Caller Infinite Allowance, Draining the DEI/USDC Pair
Loss · 5,047,470.472572 USDC (~$5.05M) drained from the DEI/USDC Solidly stable pair (one of sev…
DEI's burnFrom(account, amount) was supposed to consume the caller's existing allowance over account. Instead, the implementation wrote a fresh, near-infinite allowance…
ERC20TokenBank / ExchangeBetweenPools Exploit — Zero-Slippage Curve Swap Sandwich
Loss · ~$111,500 — 111,500.39 USDC extracted in a single transaction
ExchangeBetweenPools.doExchange() (ExchangeBetweenPools.sol:230-244) takes USDC out of a partner ERC20TokenBank, immediately market-sells all of it into the Curve yPool…
FAPEN (Father Pepe Inu) Exploit — `unstake()` Mints Free Tokens via Backwards Balance Check
Loss · ~$600 — 2.042256597375684021 WBNB drained from the FAPEN/WBNB PancakeSwap pair
FatherPepeInu collects a 1% fee on every transfer into its own contract balance (balances[address(this)]). It exposes a public function unstake(uint256 amount) that is s…
Goldseed `landNFT` Exploit — Unprotected Minter Forwarder Lets Anyone Free-Mint 200 Land NFTs
Loss · 200 land NFTs minted for free → swapped for 28,601 $XQJ → ≈ 149,616 $BUSD (~$149.6K)
landNFT correctly gates its own mint() behind an onlyMiner modifier (landNFT.sol:1592). The problem is what it whitelisted as a miner: a separate helper contract, Miner…
GPT Token Exploit — Deflationary `transfer`-Hook + `skim()` Pool Drain
Loss · ~19,989.31 BUSD extracted by the attacker (≈ the BUSD liquidity / value that was in the G…
GPT is a "reflection + auto-liquidity + buy-back-and-burn" token. Its transfer logic (triggered whenever GPT moves to/from the pair, i.e. on a swap) does three AMM-touch…
HODL Capital Exploit — Reflection-Rate Manipulation via `deliver()` Drains the Uniswap Pair
Loss · ~2.34 ETH (≈ $4.3K at the May 2023 ETH price) — drained from the HODL/WETH Uniswap-V2 pair
HODLCapital is a "reflect" (RFI-style) token. Every holder's balance is derived from a hidden double-entry ledger: a large "reflection" space (_rOwned, _rTotal) mapped d…
Jimbo Protocol Exploit — TraderJoe LB Rebalance Manipulation & Floor-Price Decoupling
Loss · ~359.16 WETH (flash-loan-funded; ≈ $639K at the May 2023 ETH price)
Jimbo is a rebasing token protocol that manages all JIMBO/WETH liquidity itself on a TraderJoe v2.1 Liquidity Book pair. Its JimboController.shift() routine is permissio…
Level Finance Exploit — Duplicate-Epoch `claimMultiple()` Reward Multiplication
Loss · 205,105.54 LVL drained from the referral controller's reward balance (≈ $1M at the May-20…
LevelReferralControllerV2.claimMultiple(uint256[] _epoches, address _to) (src_referral_LevelReferralControllerV2.sol:161-176) iterates over a caller-supplied array of ep…
LFI / VLFI Exploit — `claimRewards()` Reward-Debt Reset via Botched `cleanUserMapping` Migration
Loss · ~$36,000 (per PoC @KeyInfo) — drained as LFI (the staked/reward token) from the VLFI stak…
VLFI_8 is a MasterChef-style staking pool: stakers receive VLFI LP tokens and accrue LFI rewards proportional to balanceOf(user) × accRewardsPerShare, offset by a per-us…
LocalTrader2 (LCT) Exploit — Unprotected Proxy Implementation Lets Anyone Set the Token Price to 1 wei
Loss · 383.24 WBNB (~$110K at the time) drained from the LCT/WBNB PancakeSwap pool
The LCT vendor contract LCTExchange.buyTokens() prices its token sales by reading an external "live price" oracle: tokenAmount = (msg.value / getLivePriceFromInheritance…
LocalTraders (LCT) Exploit — Unprotected Price-Oracle Initializer Drains the LCT/WBNB Pool
Loss · ~383.24 WBNB drained from the LCT/WBNB PancakeSwap pair (≈ $120K at the May-2023 BNB pric…
LCTExchange.buyTokens() mints (well, sells) LCT at a price taken live from an external oracle: tokenAmount = (msg.value / price) * 1e18 (LCTExchange.sol:312-313). The pr…
LW Token Exploit — Spot-Price Oracle Manipulation Drains Protocol "Buyback" Treasury into the LP, Then Drains the LP
Loss · ~$50K live (two txs); the single-tx PoC nets 83,476.06 USDT (≈ $83.5K) profit
LW (deployed as contract GGGTOKEN) is a fee-on-transfer token with a homemade "price-defense" mechanism. It reads the instantaneous PancakeSwap pool ratio as its price v…
Maia DAO — Adversary can poison depositNonce via retrieveDeposit and lock user deposits
Untagged1. Attacker calls retrieveDeposit(60) with no ownership check.\n2. Root marks nonce 60 executed.\n3. User deposit with nonce 60 is rejected on root; tokens locked on bra…
Maia DAO — An attacker can steal Accumulated Awards from RootBridgeAgent by abusing retrySettlement()
1. Inside a single anyExecute (initialGas > 0), userFeeInfo.gasToBridgeOut is set once from the user's single branch-chain gas payment. 2. Each _retrySettlement calls _m…
Maia DAO — checkParams does not check token is underlying of hToken
Untagged1. checkParams requires underlying exists and hToken is local, not that they pair.\n2. Attacker deposits USDC with hToken=hEther.\n3. Root mints 10 global hEther for 10…
Maia DAO — Re-adding a deprecated gauge in a new epoch before queueRewardsForCycle() leaves gauges without rewards
1. When a gauge is deprecated (removeGauge), its weight is subtracted from _totalWeight but the gauge's own vote weight is preserved in storage. 2. Re-adding it (addGaug…
Maia DAO — redeem() in beforeRedeem uses the wrong owner parameter
Untagged1. redeem burns _owner shares but calls beforeRedeem(receiver).\n2. flywheel.accrue hits receiver (0 shares).\n3. Owner never accrues; rewards stranded in flywheel.
Maia DAO — TalosBaseStrategy#init() lacks slippage protection
Untagged1. deposit() has checkDeviation; init() does not.\n2. amount0Min/amount1Min hardcoded to 0.\n3. Price manipulation drains 99% of init deposit.
Maia DAO — User may underpay for remote call ExecutionGas (missing Anycall premium)
Untagged1. _payExecutionGas deposits gasprice gas only.\n2. Anycall charges (gasprice+premium)gas.\n3. Gap taken from other users shared executionBudget.
Melo (MEL) Exploit — Unprotected `mint()` → Infinite-Supply Pool Drain
Loss · ~$90,488 — 90,488.68 USDT drained from the MEL/USDT PancakeSwap pair
The MEL token (cERC20) exposes a public mint(address, uint256, string) function with no owner / role / minter check whatsoever (cERC20.sol:313-321). Anybody can mint an…
Multi-Chain Capital ($MCC) Exploit — Reflection-Rate Inflation via `deliver()` + `skim()`
Loss · ~10.2 WETH net profit (≈ 10 ETH, ~$19K at the time) — drained from the MCC/WETH Uniswap V…
MultiChainCapital is a SafeMoon/RFI-style "reflection" token: holder balances are stored as a reflection share _rOwned[account], and the displayed balance is computed on…
NeverFall (NF) Exploit — `sell()` Over-Redeems LP Against a Pre-Crashed Pool Reserve
Loss · ~74,250.89 USDT profit to the attacker (≈ $74.3K), drained from the NF/USDT pool's LP val…
NeverFallToken is a "DeFi-ish" deflationary token where the token contract itself manages the PancakeSwap NF/USDT liquidity on behalf of users. buy() pulls USDT from the…
NOON (NO) Exploit — Public `_transfer()` Lets Anyone Drain the AMM Pool For Free
Loss · 1.13645 WETH (~$2K) drained from the NO/WETH Uniswap-V2 pair
The NO token exposes its internal balance-moving primitive as a public function with the raw ERC-20-internal signature _transfer(address sender, address recipient, uint2…
SELLC / QIQI StakingRewards Exploit — Attacker-Chosen Reward-Valuation Token Drains the Reward Pool
Loss · ~1,983.33 QIQI drained from the StakingRewards reward pool in one transaction (PoC log At…
StakingRewards.claim(address token, address token1) (StakingRewards.sol:623-641) computes the reward payout by asking a PancakeSwap router for the spot price of the stak…
SELLC / StakingRewards Exploit — Permissionless `sell()` Drains Staked LP Tokens via a Self-Created Price Oracle
Loss · ~$95K — attacker turned 3 WBNB into 332.58 WBNB (≈ +329.58 WBNB net) by draining the prot…
StakingRewards is a yield/referral contract that holds SELLC/QIQI LP tokens (SellQILP) on behalf of its stakers. It exposes two functions with no meaningful access contr…
SellToken Exploit — Spot-Price Oracle Manipulation of a Leveraged "Short" Exchange
Loss · ~3.11 WBNB profit per cycle (≈ $1,000 at the time); attacker repeated this across the Sel…
SellToken is a self-described "decentralized short-trading exchange." A user opens a short on a token through ShortStart(), and later closes it through withdraw(). The s…
SNK Miner Exploit — Inflated Referral Reward via Just-In-Time Child Staking
Loss · The attacker minted 17,845.81 SNK of reward across 10 sock-puppet accounts in a single tr…
SNKMiner is a Synthetix-style staking farm with a multi-level referral ("community") bonus. A parent earns a dynamic reward equal to:
0VIX Protocol Exploit — vGHST Oracle Manipulation via Balance Donation
Loss · ~$2.0M — drained as ~1,453,546 USDC + ~584,445 USDT + ~9,566 GHST (flash-loaned principal…
0VIX is a Compound-V2 fork on Polygon. It accepts vGHST (Aavegotchi's auto-compounding wrapper of GHST) as collateral in the ovGHST market. The price of ovGHST's underly…
Ajna ExtraordinaryFunding — caller-supplied voter accounts drain the treasury
voteExtraordinary(account_, proposalId_) credits the nominated account's voting power rather than msg.sender. A contract can loop over every holder, reach the threshold,…
Allbridge Core Exploit — StableSwap `withdraw()` Symmetric-Burn Drain via Flash-Loan-Induced Imbalance
UntaggedLoss · ~$549,890 in this single PoC run (attacker walks away with 549,889.57 BUSD of profit); th…
Allbridge Core uses a Curve-style StableSwap pool that tracks two internal reserves: tokenBalance (real stablecoin, in 3-decimal "system precision") and vUsdBalance (a v…
Allbridge Exploit — StableSwap LP Mispricing via Self-Imbalanced Pools
Loss · ~$549,874 — 549,874.39 BUSD net profit, fully recovered intra-transaction
Allbridge's stable pools track two internal balances per pool — a real-token balance tokenBalance and a virtual-USD balance vUsdBalance (Pool.sol:2445-2446). LP shares a…
Axioma (AXT) Exploit — Mispriced Presale Sells Tokens Far Below the AMM Market Price
Loss · 20.83 WBNB profit on a single 32.5 WBNB flash-loaned buy (≈ $6.4K @ ~$310/BNB). The vecto…
AxiomaPresale.buyToken() sells AXT at a fixed, owner-set price of rate / 1e9 tokens per wei of BNB (AxiomaPresale.sol:402-418). At the time of the attack that price was…
EigenLayer — impossible to slash queued withdrawals containing a malicious strategy (misplaced ++i)
1. slashQueuedWithdrawal(recipient, queuedWithdrawal, tokens, indicesToSkip) lets the owner skip strategies in a queued withdrawal — designed so that a malicious strateg…
Frankencoin — CHALLENGER_REWARD can be used to drain reserves and free-mint ZCHF
1. Position records a liquidation price that the owner sets — at open time via _liqPrice, or later via adjustPrice. There is no upper bound. 2. When a challenge ends, Mi…
Frankencoin — Position owners can deny liquidations (unbounded price overflow)
1. A position owner can set the liquidation price arbitrarily high via adjustPrice (or the opening _liqPrice) — there is no upper bound. 2. Every challenge-resolution pa…
Frankencoin — Successful challenge + collateral top-up skips cooldown
Untagged1. On a successful challenge, internalWithdrawCollateral only extends cooldown when remaining collateral is below minimumCollateral. 2. The owner MEV-front-runs end() by…
Frankencoin — Transfer position ownership to address(0) DoSes end()
Untagged1. Owner about to lose a challenge calls transferOwnership(address(0)). 2. Winning bid creates an excess refund path in end(). 3. zchf.transfer(owner, excess) reverts be…
Hundred Finance #2 Exploit — Empty-Market Exchange-Rate Inflation Drains Every Pool
Loss · ~$7.4M across all Hundred Finance Optimism markets (ETH, SNX, USDC, DAI, USDT, sUSD, FRAX…
Hundred Finance is a Compound-v2 fork. Each CToken market prices its share token (hToken) with exchangeRate = (cash + borrows − reserves) / totalSupply (CToken.sol:357-3…
MetaPoint (POT) Exploit — Permissionless `approve()` on User-Wallet Contracts Drains Holder Balances
Loss · ~8,961.18 POT stolen from 10 holder wallets, liquidated to 83.95 WBNB (~$24K at the time;…
MetaPoint deployed a per-user "wallet" contract for each participant in its mining/pre-sale program. Each wallet holds the user's POT tokens. To let the MetaPoint backen…
OceanLife (OLIFE) Exploit — Reflection-Rate Collapse Inflates the Pool's Token Balance
Loss · 32.286 WBNB (≈ $9.7K at the time) — the entire WBNB side of the OLIFE/WBNB pair
OceanLife is a Reflect.Finance-style ("RFI") reflection token. A holder's balance is derived, not stored: balanceOf(account) = _rOwned[account] / currentRate, where curr…
Paribus Finance Exploit — Compound V2 Fork `redeemFresh` Cross-Market Reentrancy
Loss · ~$0.79M reported by analysts (this fork-PoC nets 35.23 WETH ≈ ~$66K residual after repayi…
Paribus is a Compound V2 fork. Its PToken.redeemFresh() sends the underlying out to the redeemer before it decrements the redeemer's pToken collateral balance (PToken.so…
Rubicon — DOS of market operations with malicious offers
Untaggedoffer() accepts owner/recipient=0; OZ ERC20 reverts on transfer to zero, DoSing market fills.
Rubicon — First depositor bug on unmodified Compound fork
Untagged1. Fresh CToken has totalSupply == 0 and exchangeRate = 2e26. 2. Attacker mints the minimum (2e8 underlying → 1 share), then donates a large underlying amount to the CTo…
Rubicon — Last borrowed asset is not collateralized
Untagged_borrowLoop supplies, borrows, swaps but never supplies the last swapped asset as collateral.
Rubicon — Migration can underpay users via price manipulation
Untaggedmigrate redeems V1 then mints V2 with no minOut; low-liquidity exchangeRate inflation rounds victim to 0 shares.
Rubicon — Opening a position reuses prior collateral for borrowing
UntaggedopenPosition borrow budget uses _maxBorrow which includes residual capacity from prior positions on the shared Position account.
Rubicon — Precision loss makes openPosition leverage higher than expected
Untaggedwmul floor makes desired==init; lastBorrow=0 is treated as full borrow instead of zero extra leverage.
Rubicon — RubiconMarket checks slippage incorrectly
UntaggedsellAllAmount requires fill_amt >= min_fill_amount before calcAmountAfterFee, so a post-fee floor can be violated.
Rubicon — Some offers can't be cancelled
Untagged1. SimpleMarket.offer(pay, payGem, buy, buyGem, owner, recipient) creates an offer without inserting it into the sorted _rank list or the unsorted _near list. 2. Rubicon…
Sentiment Protocol Exploit — Balancer Read-Only Reentrancy Inflates LP-Collateral Price
Loss · ~$1.0M total. In this fork run the attacker walked off with 538,399.33 USDC + 360,000 USD…
Sentiment is an over-collateralized lending protocol that lets users deposit Balancer LP tokens (BPT) as collateral. The price of a Balancer weighted-pool LP token is co…
Silo Finance Logic-Error Exploit — Interest-Rate Manipulation Drains the Entire XAI Market for ~$0
Loss · The PoC borrows the entire XAI market — 450,000 XAI for essentially zero cost. (XAI was a…
Silo is a shared-lending protocol where one Silo contract holds several markets (WETH, LINK, XAI, …) that share collateral. To decide how much you may borrow, _validateB…
Sushi RouteProcessor2 Exploit — Attacker-Controlled "Pool" Drains Approved Tokens via `uniswapV3SwapCallback`
Loss · ~$3.3M aggregate across all affected approvers (PoC drains 100 WETH from one victim as a…
RouteProcessor2 is the Sushi aggregator's on-chain route executor. To swap on a Uniswap-V3-style pool it reads the pool address straight out of the caller-supplied route…
Swapos V2 Pair Exploit — Broken `k`-Value Invariant Lets 10 wei of WETH Drain ~98% of the Pool's SWP
Loss · Not stated in the trace; the PoC extracts 142,658.16 SWP (~97.9% of the pair's SWP reserv…
SwaposV2Pair.swap() implements the Uniswap-V2 constant-product check but with the wrong scaling factors (contracts_SwaposV2Pair.sol#L180-L182):
Yearn / iEarn yToken Exploit — APR-Oracle Routing + bZx Donation Inflates Price-Per-Share for ~$11.5M
Loss · ~$11.5M — the PoC ends with 1,964,642.66 USDC + 1,780,391.61 DAI + 1,369,200.11 yTUSD (≈$…
The legacy iEarn/yearn yTokens (yUSDT, yDAI, yUSDC, yTUSD) auto-route deposits to whichever lending venue currently offers the highest APR, chosen by IEarnAPRWithPool.re…
BIGFI Exploit — Reflection-Token `burn()` That Shrinks Supply Without Shrinking Reflection Space
Loss · 30,306.103328283570349973 USDT drained from the BIGFI/USDT PancakeSwap pair — tx 0x9fe190…
1. BIGFI is a reflection-token (the DxMint "DxBurn" template, RDeflationERC20). It keeps balances in two spaces: a reflection space (_rOwned, summed by _rTotal) and a re…
DBW Finance Exploit — Dividend Reward Double-Claimed via 18 Proxy Clones Each Holding ~100% of the LP
Loss · +21,699.52 USDT attacker profit (the PoC logs the full ending USDT balance; the attacker…
DBW pays "static income" (dividends) to users who pledge PancakeSwap DBW/USDT LP tokens. The payout of getStaticIncome() is sized by the pledgor's share of total pledged…
DKP Exchange Exploit — Flash-Loan-Manipulated AMM Price Oracle Lets 100 USDT Buy the Whole DKP Reserve
Loss · +80,512.62 USDT attacker profit (profit-only, see accounting below) — attacker put in 0 n…
DKPExchange.exchange(amount) lets a user swap USDT → DKP at an internally-computed rate. The PoC header and trace show that this rate is derived from the instantaneous r…
Euler Finance $197M Exploit — `donateToReserves` Enables Self-Liquidation That Drains the Protocol's Reserves
Loss · ~$197M (this PoC extracts 8,877,507.35 DAI net after repaying a 30M DAI flash loan; the p…
Euler's EToken accounting keeps a per-asset totalBalances (sum of eToken balances) and internalBalance per user. Two functions matter:
Mute.Io — Bond max-buyer might end up buying the max buy of the next epoch
Untaggeddeposit(..., max_buy=true) ignores the caller's intended epoch and always takes the current epoch's remaining max. If the epoch rolls before inclusion, the buyer silentl…
Mute.Io — dMute: attacker can push lock items to victim's array
UntaggedAnyone can LockTo dust for any address, inflating their lock array. RedeemTo iterates the entire array even when redeeming one index, so enough spam makes redeem exceed…
ParaSpace Exploit — ApeCoin-Staking (cAPE) Collateral Mis-Accounting + Same-Tx Supply→Borrow
Loss · Mar 2023 ParaSpace incident. The PoC ends with the attacker holding ~2,906.39 WETH (outpu…
1. ParaSpace treats the cAPE token (0xC5c9fB6223A989208Df27dCEE33fC59ff5c26fFF) — an ERC4626-style wrapper over an ApeCoin-Staking position — as priceable collateral. It…
ParaSpace Exploit (variant 2) — ApeCoin Staking Supply/Borrow Reentrancy
UntaggedLoss · part of the Mar 2023 ParaSpace incident; tx 0xe3f0d14c…
ParaSpace valued BAYC/MAYC collateral including the ApeCoin staked on the NFTs. The attacker supplys an NFT whose ApeCoin staking position makes the collateral appear ov…
Phoenix (PHX) Exploit — Missing Access Control on `delegateCallSwap(bytes)`
Loss · ~$1M+ USDC drained on-chain in the real attack. The bundled PoC reproduces a scaled-down…
1. phxProxy is a delegatecall proxy whose logic implementation exposes a function delegateCallSwap(bytes data) that executes arbitrary calldata in the proxy's own contex…
Polynomial — Exchange._liquidate burns too much powerPerp
When ShortCollateral caps collateral returned on an underwater short, Exchange still burns the full debtRepaying of powerPerp from the liquidator
Polynomial — Hedging during liquidation over-hedges the LiquidityPool
Liquidation already balances short inventory and powerPerp burn, but pool.liquidate still hedges again and burns pool funds as fees
Polynomial Protocol — division-by-zero in getTokenPrice bricks KangarooVault with funds locked
1. getTokenPrice returns totalFunds.divWadDown(totalSupply) when totalFunds != 0 and positionId == 0, with no guard for totalSupply == 0. 2. That state is reachable: aft…
Polynomial Protocol — KangarooVault.removeCollateral updates storage without removing collateral
1. addCollateral transfers collateral to the Exchange and increments usedFunds / positionData.totalCollateral — real assets move. 2. removeCollateral decrements the same…
Polynomial Protocol — missing totalFunds update in LiquidityPool.openShort shortchanges LP holders
1. openShort charges the trader a fee by paying out only totalCost = tradeCost - fees, so the pool keeps the fee. 2. Of that fee, externalFee goes to the dev/hedge and t…
Polynomial Protocol — short positions can be burned while still holding collateral
1. ShortToken.adjustPosition writes the new shortAmount, then burns the position's ERC721 whenever shortAmount == 0. 2. It never checks collateralAmount. A position can…
Polynomial Protocol — uneven performance-fee deduction shortchanges late KangarooVault holders
1. While a position is open, getTokenPrice values the vault as totalFunds + premiumCollected + … and subtracts usedFunds + markPrice*short — but not the performanceFee t…
Poolz LockedDeal Exploit — Integer Overflow in `getArraySum` Crediting Free Vesting Pools
Loss · ~$390K — multiple Poolz vesting tokens (MNZ, SIP, WOD, ECIO) drained on BSC. PoC ends wit…
LockedDeal is a Poolz token-vesting contract compiled with Solidity 0.6.12, which does not revert on integer overflow. The vesting logic correctly uses SafeMath.add/sub…
SafeMoon Exploit — Unprotected `burn(from, amount)` Drains the AMM Pair Reserve
Loss · 27,463.848 WBNB (≈ $8.9M at the time) — the entire WBNB side of the SFM/WBNB SafeSwap pai…
1. SafeMoon V1's implementation exposes burn(address from, uint256 amount) as a public function with no onlyOwner, no onlyWhitelist, and no allowance check (Safemoon.sol…
Thena RewardPool Exploit — Reentrant `unstake(…, claim=true)` Double-Payout of Converted Rewards
Loss · 10,197.896 BUSD (≈$10.2K) drained from the wUSDR gauge reward pool in the reproduced PoC;…
1. The Thena gauge (ThenaRewardPool) is an ERC1967 proxy at 0x39E29f4F… that delegatecalls the gauge logic 0xaEDb0094…. Its unstake(address token, uint amount, address r…
BonqDAO / AllianceBlock Exploit — `TellorFlex` Oracle Price Manipulation (Cheap-Stake `submitValue`)
Loss · ~$88M — 100,514,098.34 BEUR minted from BonqDAO in Tx1 + 113,813,998.37 ALBT (as wALBT) s…
BonqDAO is a Polygon CDP (Liquity-style "Trove") protocol that prices its collateral token wALBT straight off a TellorFlex oracle. TellorFlex is a reporter/stake oracle:…
CowSwap `SwapGuard` Exploit — Unvalidated Interaction Target in `envelope()` (arbitrary `transferFrom` under maxint `allowedLoss`)
Loss · 114,824.890807160711319588 DAI (= 114,824,890,807,160,711,319,588 wei) drained from the G…
1. SwapGuard.envelope(Data[]{target,value,callData}, vault, tokens, tokenPrices, balanceChanges, allowedLoss) is a generic "execute these calls and then check the vault…
Dexible Exploit — Caller-Controlled `router`/`routerData` in `selfSwap`/`fill`
Loss · ~$1.5M — at least 1,796,093.75 TRU drained from a single victim in the reproduced PoC (ou…
Dexible is a meta-aggregator/relayer: a trader signs an order, a relayer submits it, and Dexible's swap()/selfSwap() walks an array of RouterRequest hops calling each ro…
dForce Exploit — Read-only Reentrancy via Curve `remove_liquidity` into the dForce Price Oracle
Loss · ~$3.65M — drained from dForce's Arbitrum wstETHCRV-gauge collateral market (VWSTETHCRVGAU…
dForce's Arbitrum money market accepted vaulted wstETH/CRV-gauge tokens (VWSTETHCRVGAUGE) as collateral and priced them through PriceOracleV2.getUnderlyingPrice(). That…
DYNA (Dynamic) Exploit — Reward-Inflation in `StakingDYNA.deposit`/`redeem` + Time-Bypassable Sell Cap
Loss · ~65.44 WBNB drained from the DYNA/WBNB PancakeSwap pair — 65,440,735,110,133,004,365 wei…
StakingDYNA (StakingDYNA.sol) computes interest as principal × apr × (now − lastProcessAt) / YEAR / 10000 (StakingDYNA.sol:67-77). The bug is in how a follow-up deposit…
EFVault / ENF Exploit — `redeem()` Share-Price Decimal Bug Drains USDC
Loss · 3,436,919.309773 USDC (3,436,919,309,773 raw, 6-dec) drained from the Euclid/ENF USDC vau…
EFVault (contracts_core_Vault.sol) is an ERC-4626-style share/asset vault. The ENF token at 0xBDB515… is a TransparentUpgradeableProxy that delegates to this EFVault log…
FDP (FireDrake) Exploit — Reflective-Token `deliver()` Inflates the AMM Pair's Balance
Loss · ~16.18 WBNB drained from the FDP/WBNB PancakeSwap pair (the PoC prints Attacker's profit:…
FDP (source) is a reflective (a.k.a. "t-token / r-token") BEP20: it keeps two ledgers per address — an r-space balance (_rOwned) and a t-space balance (_tOwned) — and ex…
LaunchZone (LZ) Exploit — Unverified `swapXImp` Logic Flaw (Permissionless Victim-Side Swap)
Loss · ~88,849.89 BUSD reproduced from a single victim in this PoC (the live attack across all v…
LaunchZone had quietly upgraded its swapX proxy to an unverified implementation (swapXImp, 0x6D898184…). That implementation exposes a swapX(bytes,transferAmount,value,b…
Mass — low-level call to an empty account falsely succeeds
The helper accepts delegatecall success from an account with no code. EVM semantics return true for an empty destination, so the caller observes success without executin…
Orion Protocol Exploit — Reentrancy via Malicious Deposit Token in `swapThroughOrionPool` / `depositAsset`
Loss · ~$2.84M USDT on Ethereum (PoC) + a parallel BSC incident; the verified PoC drains 2,836,2…
1. Orion runs a brokerage-style exchange: users depositAsset to move real ERC20s into Orion's wallet, and Orion keeps a per-user virtual balance ledger (getBalance). Tra…
Platypus Finance Exploit — Flawed LP-Collateral Pricing in `PlatypusTreasure` (`_getLPUnitPrice`)
Loss · ~$8.5M — the attacker borrowed 41,794,533 USP of unbacked debt against 44M USDC of LP col…
Platypus is an Avalanche stableswap whose Pool mints LP-asset tokens (LPUSDC, etc.), and a sister contract PlatypusTreasure accepts those LP tokens (staked in MasterPlat…
Revert Finance (V3Utils) Exploit — Unvalidated `swapData` Lets Anyone Route User-Allowance Tokens to an Attacker
Loss · 19,805.581627 USDC (raw 19,805,581,627, 6 decimals) drained from two users who had approv…
1. Revert Finance's V3Utils is an ownerless, "stateless" helper that users grant ERC20 allowances to so it can compound/swap/withdraw on their Uniswap-V3 positions. Its…
Sheep Exploit — Reflective-Token `_burn` Distorts `balanceOf`, Drains SHEEP/WBNB Pair via DODO Flash
Loss · ~16.394 WBNB drained from the SHEEP/WBNB PancakeSwap pair — Attacker WBNB balance after e…
1. SHEEP is a reflection token (CoinToken, an RFI-style contract). It keeps two parallel supplies: a "reflection" supply _rTotal (~2^256 / totalSupply per token) and a "…
Sperax USDs Exploit — `isContract()`-Based Rebase Accounting Flip on a Pre-Credited EOA
Loss · USDs supply inflation — the PoC mints 11 USDs and observes a balanceOf of 9,797,854,216,5…
USDs is a rebasing ERC20. It does not store face-value balances; instead it stores an internal credit balance per account and converts credits ↔ USDs through an exchange…
Starlink (Starlink Coin) Exploit — Reflective Token Fee vs. Pancake `skim`/`sync` Reserve Drain
Loss · 38.359839689566733894 WBNB drained from the Starlink/WBNB PancakeSwap pair — the pool's e…
1. StarlinkCoin (source) is a reflective ERC20 with a 9-decimal unit and a directional fee: every transfer into the Pancake pair (recipient == uniswapV2Pair) is taxed at…
SwapX Exploit — Unverified `swapX` Router Drains Pre-Approved Victim BUSD via Caller-Controlled Recipient
Loss · ~119,481 BUSD drained from 14 victim EOAs (119,481,398,039,170,502,254,309 wei, summed fr…
SwapX is a BSC swap router whose swapX entrypoint (function selector 0x4f1f05bc) is unverified on BscScan — the same un-audited implementation family as the LaunchZone i…
Unprotected `CALLCODE` lets anyone destroy the Nested Finance HyVM master
BEVO Exploit — Reflective-Token `deliver()` Pool-Balance Inflation Drain (PancakeSwap Flash)
Loss · 144 BNB (~$40K) — tx 0xb97502d3…
BEVO is a "reflective" (rebasing-fee) ERC20 that keeps two ledgers: a real balance and a much larger reflection balance (_rOwned, scaled by _rTotal / _tTotal). A holder'…
BRA Token Exploit — `_transfer` Buy/Sell Tax Credited to the Pair Itself, Drained via `skim()`
Loss · ~819 BNB (~$224K) across two txs — 0x6759db55… (675 WBNB, reproduced here) + 0x4e5b2efa……
1. BRAToken._transfer (BRAToken.sol:428-476) applies a buy tax when sender == uniswapV2Pair and a sell tax when recipient == uniswapV2Pair. The two checks are two indepe…
GDS Coin Exploit — Spot-Price `pureUsdtToToken` Reward Inflation via Nested Flash Loans (BSC)
Loss · ~207,248.32 USDT net profit to the attacker (≈ $207K at the time). Raw-wei figure logged…
1. GDSToken.pureUsdtToToken(uAmount) is a view that quotes a USDT amount into GDS by calling the PancakeSwap V2 router's getAmountsOut on the live GDS/USDT pair (sources…
Midas Capital Exploit — Reentrancy-inflated Curve-LP Oracle for stMATIC Collateral (Compound v2 fork, Polygon)
Loss · ~$6.6M across multiple Midas markets on Polygon (the PoC reproduces the core drain of 4 m…
Midas is a Compound v2 fork whose Fuse pools price a WMATIC_STMATIC cToken collateral by delegating through MasterPriceOracle to a leaf oracle (0x3803527d…) that derives…
OmniEstate Exploit — Staking Reward Calculated From a Stale Storage Variable (Zero-Duration Over-Claim)
Loss · ORT minted to the attacker for free. The PoC seeds 1 WBNB and ends with 1.120132465266157…
1. OmniStakingPool.invest(end_date, qty_ort) accepts any end_date, but only the four values 3, 6, 12, 24 actually set duration[msg.sender] and end_staking[msg.sender] (S…
QTN (QUATERNION) Exploit — Reflection-Supply Rebase Inflation via `skim()` Loop
Loss · WETH drained from the QTN/WETH Uniswap-V2 pair across two txs — 0x37cb8626… and 0xfde10ad…
QUATERNION (QTN) is a reflection-style ERC20 that keeps balances internally as "gons" (_gonBalances[addr]) and converts to user-facing QTN via _gonsPerFragment = TOTAL_G…
ROE Finance Exploit — Manipulatable LP-Token Oracle + Re-deposit Collateral Inflation
Loss · ~$64,121 — 64,121.353617 USDC drained from ROE's USDC reserve (output.txt:7)
1. ROE Finance was a near-verbatim Aave-v2 fork whose LendingPool (deposit, borrow) shipped with the standard validateBorrow health-factor check (ValidationLogic.sol#L12…
SHOCO Exploit — Reflection `deliver()` Deflation Inflates the AMM Pair's Effective Balance
Loss · ~4.30 ETH — 4.301834963160736116 WETH drained from the SHOCO/WETH Uniswap V2 pair (output…
Shoco (Shoco.sol) is a "reflective" / "rebasing" ERC20 (a TaxToken-style contract) that maintains two parallel supplies: a true supply _tTotal and a larger "reflection"…
Thoreum Finance Exploit — Dividend/Rebase Token Self-Transfer Balance Inflation
Loss · ~2,000 BNB across the full Jan-2023 incident; 6.11 WBNB (= 6.109951473560231892 WBNB) ext…
Thoreum (0xce1b3e…) is an ERC1967 proxy whose hidden implementation (0x79Fe…AF4F, never verified on BscScan) behaves as a dividend-distributing fee-on-transfer token. On…
Timeswap V2 — collect() always transfers zero fees then burns the fee position
Untaggedcollect() always transfers zero fees then burns the fee position. Harm demonstrated: Fee position burned while pool transfers zero fees — permanent fee loss.
Timeswap V2 — LiquidityToken uses `totalSupply()+1` as tokenId (collision after burn)
1. TimeswapV2LiquidityToken.mint assigns a new position's ERC-1155 tokenId with id = totalSupply() + 1. 2. totalSupply() (from ERC1155Enumerable) is _allTokens.length, w…
TomInu (TINU) Exploit — Reflective-Token (RFI) Reflection-Rate Skim against a Uniswap-V2 Pair
Loss · ~22 WETH — attacker's final WETH balance 22134561461014981232 wei (~22.134561 WETH) after…
TomInu (TomInu.sol:663) is a "reflective" (RFI-style) ERC20: every balance is stored twice — a reflection balance _rOwned and a real balance _tOwned — and balanceOf() de…
UFO/UFDao (UFT) Exploit — Treasury-Share Mispricing on a Tiny-Supply LP Token
Loss · ~$90,070 USDC — 90,070.588320368098073575 USDC drained from the UF DAO treasury (tx)
1. UFO/UFDao ("UF") is a DAO-as-a-service vault. Each DAO holds a treasury of tokens at its own contract address and issues an ERC-20 LP token (here UFT, 0xf887A2…) whos…
Upswing (UPS) Exploit — `sellPressure` Farming + `releasePressure()` LP-Burn That Breaks `k`
Loss · ~22 ETH in the live mainnet attack (per the PoC's @KeyInfo header). The bundled PoC is a…
1. UpSwing is an ERC20 with a "reflexive" deflation mechanic. Every UPS transfer whose recipient is the Uniswap-V2 pair (UNIv2) bumps the sender's per-holder txCount and…
AES (AEST) Exploit — Fee-Accumulator `distributeFee()` Drains the AMM Pair
Loss · ~61,608 USDT (~$61.6K) drained from the AES/USDT PancakeSwap pair
AEST is a deflationary token that, on every buy/sell, silently burns 3% of the moved amount and credits 1% of the moved amount into a public accumulator swapFeeTotal (AE…
APC (ArenaPlay) Exploit — Spot-AMM-Price Swap Drained via Flash-Loan Pump & Dump
Loss · PoC reproduces +7,626.99 USDT profit in one cycle; the two live attacks (referenced in th…
The ArenaPlay (APC) project ships an internal swap(fromToken, toToken, amount) contract (behind a TransparentUpgradeableProxy) that lets users trade APC ↔ MUSD. Instead…
BBOX Token Exploit — Fee-Engine Burns Tokens Out of the LP Pair and `sync()`s
Loss · ~38.44 WBNB (~$10.8K at the time) drained from the BBOX/WBNB PancakeSwap pair
BBOXToken (BBOXToken.sol) is a "share-dividend" deflationary token whose _transfer maintains a state variable pairAmount (intended to track fees that should be removed f…
BGLD (BlackGold) Exploit — Migration-Contract Inflation + AMM Reserve Manipulation
Loss · ~18,063.36 USDT + 8.80 WBNB leftover (attacker ends with both)
BlackGoldMigration.migrate() lets a user convert old BGLD (v1) into new BGLD (v2) 1:1 plus a 10% bonus. The catch is that v1 is a fee-on-transfer token: moving N tokens…
Defrost Finance `lendingSwitchErc20` Exploit — Reentrant Flash-Loan Share Inflation
Loss · ~173,635.82 USDC drained from the Defrost lendingSwitchErc20 (LSW) vault
Defrost's lendingSwitchErc20 vault implements an ERC-3156 flash loan whose flashLoan() (baseSuperToken.sol:167-183) runs the balance mutation onWithdraw() before it call…
DFS Exploit — `_transfer` Accounting Gap Let `skim()` Self-Loop Mint DFS Out of Thin Air
Loss · ~1,452 USDT (≈ $1,450) drained from the DFS/USDT PancakeSwap pair
The DFS token implements a custom _transfer that, whenever the PancakeSwap pair is the from or to, tries to take a 0.5 % fee. The branching is written so that if the fee…
ElasticSwap Exploit — Internal-Reserve Manipulation Drains the TIC/USDC.e AMM
Loss · 187,460.63 USDC.e drained from the TIC/USDC.e pool (+ 40,607.38 TIC residual). The origin…
ElasticSwap's Exchange keeps an InternalBalances struct (baseTokenReserveQty, quoteTokenReserveQty, kLast) separate from the real ERC-20 balances, so it can cope with el…
FPR Token Exploit — Public `setAdmin()` Hijack Drains FPR Distributor Contracts + LP
Loss · ~$28,095 (28,094.70 USDT) drained from FPR distributor contracts + the FPR/USDT PancakeSw…
FPR is a deflationary BEP-20 token whose project deployed a handful of "distributor" contracts that hold FPR (and, in one case, the FPR/USDT PancakeSwap LP tokens) and e…
JAY Token Exploit — Reentrancy via Attacker-Controlled "ERC721" Callback in `buyJay`
Loss · ~15.32 ETH (attacker's net profit, fully flash-loan funded)
JAY is a do-it-yourself AMM: users send ETH in and get minted JAY at a bonding-curve price (ETHtoJAY), and they burn JAY to redeem ETH back out (JAYtoETH). The price of…
Lodestar Finance Exploit — `plvGLP` Oracle Inflation Drains the Lending Pools
Loss · ~$6.5M drained from Lodestar's lending pools (~2.8M GLP / ~$2.4M of it later flagged reco…
Lodestar priced its plvGLP collateral with a GLPOracle that read the on-chain share price of PlutusDAO's PlvGlpToken — an OpenZeppelin ERC-4626 vault whose price-per-sha…
MEV Bot 0x28d9 Exploit — Flash-Loan Callback Hijack via Attacker-Controlled `assetTo`
Loss · ~2,670.98 USDC (2,670,984,488 µUSDC) — the victim's entire USDC-side proceeds; drained 16…
The victim is an MEV/arbitrage bot (0x28d9) that holds ~2.67M USDT and is designed to act as a DODO flash-loan callback receiver. When a DODO pool calls IDODOCallee.DSPF…
MUBank Exploit — Flash-Swap Manipulation of Reserve-Dependent Bond Pricing
Loss · ~48,670.71 USDC.e drained from MUBank's reserves (MU + MUG tokens)
MuBank.mu_bond() and mu_gold_bond() let anyone deposit an approved stablecoin (USDC.e) and receive the protocol's MU / MuGold tokens at a price quoted off the instantane…
Nimbus Platform Exploit — Flash-Loan AMM Spot-Price Manipulation of Staking Rewards
Loss · ~$370K reported (SlowMist). PoC nets 323.57 WBNB of self-recovered profit on the fork; th…
The three Nimbus staking contracts pay rewards denominated in one token but price those rewards through PriceFeed.queryRate(), which ultimately derives its answer from t…
Nova Exchange Exploit — Owner-Only Unlimited Mint via `rewardHolders()`
Loss · The token's value was rugged via unlimited owner minting; the PoC demonstrates the owner…
Nova Exchange's token contract ships a function literally named rewardHolders(uint256 amount) (Nova.sol:414-417) that is gated only by onlyOwner and does exactly two thi…
Overnight Finance USD+ Exploit — NAV Inflation via Synapse Stable-Pool Manipulation
Loss · +144,303 USDC net to the attacker (36,000 → 180,303 USDC). The full real-world incident a…
USD+ is a rebasing/yield stablecoin: you buy() it with USDC and you can redeem() it back. The protocol decides how much real value sits behind every USD+ by reading the…
RFB (Roast Football) Exploit — Brute-Forceable On-Chain "Lucky Buyer" Jackpot Drain
Loss · +12.171906 WBNB net profit to the attacker, captured per single flash-loaned transaction…
RFB is a meme token with a built-in "lucky buyer" lottery. On every buy from the AMM pair, _transferFrom calls luckyNum[recipient].push(randMod(recipient, amount)) (RFB.…
Rubic Exchange Exploit — Arbitrary External Call Drains User Allowances
Loss · ~$1,475,491 USDC (1,475,491.811413 USDC) skimmed from users who had approved the Rubic pr…
RubicProxy is a cross-chain aggregator. To bridge or swap, a user first approves the proxy to spend their tokens, then the proxy forwards the trade to an external "route…
TiFi Finance Exploit — Spot-Price Oracle Manipulation of a Lending Pool
Loss · ~87.14 WBNB (≈ $24k at the time; SlowMist/PeckShield reported ~$722K total across the TiF…
LendingPool values every user's collateral and debt with getPriceWBNB(), which for any non-WBNB token calls GetPrice.getTokenToBNBPrice(token). That helper returns the i…
Abracadabra / Kashi Cauldron Exploit — Self-Liquidation Against a Stale Exchange Rate
Loss · ~99,017.79 MIM (≈ $99K) extracted from the xSUSHI Cauldron's liquidity in a single flash-…
The Abracadabra Cauldron lending market uses two different snapshots of the same exchange rate within one transaction:
Annex Finance `Liquidator` Exploit — Unauthenticated Flash-Swap Callback Drains the Contract
Loss · ~7.2224 WBNB drained from the Liquidator contract (the entire WBNB balance it held at the…
Liquidator is a flash-loan liquidation helper for the Annex Finance lending market (a Compound/Venus fork on BSC). To liquidate underwater borrowers it borrows the repay…
Aurum Finance (AUR) Exploit — Unprotected `changeRewardPerNode()` Drains the Node-Reward Pool
Loss · ~$13.4K — 49.85 BNB profit (the entire AUR balance of the node pool, swapped to BNB)
AurumNodePool is a "node-as-a-yield" contract: users pay AUR to create "nodes," and each node accrues AUR rewards over time at a rate of rewardPerDay. The reward owed to…
BDEX (Bvaults) Exploit — Permissionless `convertDustToEarned()` Sandwiched into a No-Slippage Pool Swap
Loss · 16.22 WBNB extracted from the BDEX/WBNB pair in a single transaction (~$4.6K at the Nov-2…
BvaultsStrategy is a Bvaults yield-strategy contract that periodically converts leftover "dust" balances into its earnedAddress token so they get reinvested on the next…
Beefy "Moo CAKE CTX" Vault Exploit — Harvest-Sandwich Reward Theft
Loss · 29,913.7 CAKE net to the attacker (~$142K at the time) — drained from honest vault deposi…
BeefyVault is an auto-compounding CAKE vault. Share price is getPricePerFullShare() = balance() 1e18 / totalSupply() (BeefyVault.sol:872-874), where balance() reads the…
Brahma Finance (BrahTOPG) Zapper Exploit — Arbitrary `call` Drains User Approvals
Loss · ~$79,680 — 79,679.661825 USDC pulled from a single approver (the live incident totalled ≈…
Zapper.zapIn() is designed to let a user "zap" any token into the vault by performing a swap on a DEX/aggregator. To make that swap generic, the Zapper takes the swap ta…
DeGate — arbitrary token integration can lock deposits
Any user can add a token before its special balance check is enabled. A 10% deflationary transfer credits 100 while only 90 arrives, leaving the credited withdrawal perm…
DFX Finance Exploit — Reentrancy via Unguarded `flash()` Inflates LP Share Mint
Loss · ~170,669.64 USDC drained from the XIDR/USDC DFX Curve pool (the full incident, across mul…
DFX's Curve stableswap pool added a Uniswap-V3-style flash() loan (contracts_Curve.sol:634-669). Every value-bearing entry point on the pool (deposit, withdraw, originSw…
MBC / ZZSH Exploit — Public `swapAndLiquifyStepv1()` Lets an Attacker Inject the Token's Own Accumulated Fees Into the Pool Reserve
Loss · 5,930.68 USDT profit to the attacker (extracted across two identical tokens in one tx)
MBC and ZZSH are two near-identical deflationary "fee-on-transfer" tokens. Each charges a ~5–8% tax on swaps; part of that tax (ldxRate, 4% for MBC) is collected inside…
MEV Bot `0x0AD8…afd4` — Arbitrary-Call Router Drains a Victim's Standing USDC Approval
Loss · 91,638.11 USDC (~$91.6K) — the victim's entire USDC balance
The contract at 0x0AD8…afd4 is a generic "MEV bot / swap router" that exposes a function — selector 0x090f88ca — which takes a caller-supplied bytes blob and executes it…
Multichain (Anyswap) `anySwapOutUnderlyingWithPermit` — Missing-`permit` Allowance Theft
Loss · 557,754.45 NUM swapped out → attacker netted 13,822.28 USDC in this single reproduced tx;…
Multichain's AnyswapV4Router.anySwapOutUnderlyingWithPermit() is supposed to let a user authorize a cross-chain transfer with a single EIP-2612 signature: the router cal…
ParaSpace — [H-01] Data corruption in NFTFloorOracle; Denial of Service
Untagged1. Remove feeder B (middle): last feeder C is swapped into B's slot. 2. feederPositionMap[C].index still says 2 while array length is 2. 3. removeFeeder(C) reads feeders…
ParaSpace — [H-03] Interest rates are incorrect on Liquidation
1. _burnDebtTokens safeTransferFroms the repayment into the xToken, then calls updateInterestRates(liquidityAdded). 2. calculateInterestRates does balanceOf(xToken) + li…
ParaSpace — [H-04] Anyone can prevent themselves from being liquidated
Untagged1. Comment says owner-only; modifier is only onlyWhenFeederExisted. 2. Anyone removes all feeders → no one can setPrice (UPDATER_ROLE revoked). 3. Liquidations that need…
ParaSpace — [H-05] Attacker can manipulate low-TVL Uniswap V3 pool to borrow
Untagged1. Any UniV3 position whose tokens are listed can be collateral. 2. Value = token amounts in the position × external oracle prices (no pool TVL check). 3. Attacker owns…
ParaSpace — [H-08] NFTFloorOracle asset and feeder structures can be corrupted
Untagged1. Asset indices stored as uint8; assets never shrinks on remove (delete only). 2. After 256 assets, the next add stores uint8(256) == 0. 3. removeAsset then zeros the w…
ParaSpace — [H-09] UniswapV3 tokens of certain pairs will be wrongly valued
Untagged1. Same-decimal branch: sqrt(token0Price 1e18 / token1Price) 2^96 / 1e9. 2. If token1Price > token0Price * 1e18, inner div is 0 → sqrtPriceX96 = 0. 3. Amount math treats…
ParaSpace — [H-10] Attacker can drain pool using executeBuyWithCredit
Untagged1. Pool charges the user from OrderInfo consideration built with maker price. 2. LooksRare exchange transfers taker price from the pool to the maker. 3. Attacker is both…
ParaSpace — flash-loan bypass of the auction recovery health check
Loss · Auction recovery can be cancelled while the borrower has no lasting recovery collateral;…
ParaSpace checks that the NFT account is above the recovery threshold only at the instant setAuctionValidityTime() executes. A borrower can flash-borrow 1,000 WETH, supp…
Polynomial Protocol Exploit — Arbitrary `swapTarget.call` Drains Pre-Approved User Funds
Loss · ~$1.4K — 209.167120 USDC swept from 5 users who had approved the Zap
PolynomialZap.swapAndDeposit() is a "zap" helper meant to take a user's token, route it through an arbitrary DEX aggregator, and deposit the proceeds into a Polynomial v…
sDAO Exploit — Staking-Reward Accounting Manipulation via Self-Inflated `totalStakeReward` + Shrunken Reward Divisor
Loss · ~13,162 USDT profit to the attacker (final balance 13,661.9 USDT, minus the 500 USDT flas…
sDAO bolts a "stake the LP token, earn SDAO rewards" feature onto an ERC-20. The reward math has two independently-attacker-controlled inputs and zero protection:
SEAMAN Exploit — Forced Tax-Swap Routed Through a Thin GVC Pool (Price Manipulation)
Loss · ~$7,782 — 7,781.78 USDT net profit for the attacker (BSC-USDT)
SEAMAN is a "tax + dividend" token. Whenever anything is transferred to its SEAMAN/USDT PancakeSwap pair, its _transfer hook fires swapAndLiquifyV3() and swapAndLiquifyV…
SheepFarm Exploit — Free Gems via Repeatable `register()`
Loss · ~3.0556 BNB drained from the SheepFarm bank (≈ $880 at the Nov-2022 BNB price, the game's…
SheepFarm is a BNB "miner" game: you buy gems, spend gems to upgrade sheep farms, the farms produce wool (money) over time, and you withdraw wool back into BNB at a fixe…
SheepFarm Exploit — Free-Gem Mint via Repeatable `register()`
Loss · ~$80K total across many bots in the wild; this single PoC tx nets 0.098 BNB (~$26 at the…
SheepFarm is a BNB "play-to-earn" idle game. Players buy gems with BNB (addGems), spend gems to upgrade their village (upgradeVillage), accrue wool/money yield, and cash…
Stakehouse `Syndicate.unstake` leaves the reward claim-debt snapshotted at the pre-unstake balance
UntaggedStakehouse Protocol — `bringUnusedETHBackIntoGiantPool` can cause stuck ether funds in the Giant Pool
1. A depositor supplies ETH to the Giant Pool via depositETH. idleETH tracks "ETH available for withdrawal or staking" and is incremented. 2. The pool stakes that ETH in…
Stakehouse Protocol — `bringUnusedETHBackIntoGiantPool` loses idleETH addition and lets attackers steal ETH from the Giant Pool
1. totalRewardsReceived() is address(this).balance + totalClaimed - idleETH. 2. batchDepositETHForStaking correctly does idleETH -= amount when capital leaves. 3. bringU…
Stakehouse Protocol — `withdrawETH` from `GiantMevAndFeesPool` can steal most of the ETH because `idleETH` is reduced before burning the LP token
1. GiantPoolBase.withdrawETH does, in this exact order: idleETH -= _amount; then lpTokenETH.burn(msg.sender, _amount); then a plain ETH transfer of _amount to msg.sender…
Stakehouse Protocol — GiantLP with a `transferHookProcessor` can't be burned, users' funds stuck in the Giant Pool
1. GiantLP calls transferHookProcessor.beforeTokenTransfer(_from, _to, amount) on every mint/burn/transfer whenever a hook processor is set. 2. GiantMevAndFeesPool (whic…
Stakehouse Protocol — incorrect accounting in `SyndicateRewardsProcessor` lets any LP holder steal others' ETH from the fees and MEV vault
1. _distributeETHRewardsToUserForToken computes due = (accumulatedETHPerLPShare * balance / PRECISION) - claimed[_user][_token] — the user's total accrued entitlement mi…
Stakehouse Protocol — repeated reward claims drift, letting a curator extract more than their fair share
1. _distributeETHRewardsToUserForToken computes due — the ETH newly owed to a user — as accumulatedETHPerLPShare * balance / PRECISION - claimed[user][token], and pays i…
Stakehouse Protocol — transferring GiantMevAndFeesPool tokens leaves claimed[] high, DoS-ing the sender and orphaning future rewards
1. claimed[user][token] records how much a user has already been paid for their LP. 2. On GiantLP transfer, rewards are settled for the sender, balances move, then after…
UEarnPool Exploit — Self-Referral `claimTeamReward()` Inflation Drain
Loss · ~$2.24M of protocol USDT siphoned in-tx; attacker net profit ≈ 16,265.90 USDT after repay…
UEarnPool pays a "team reward" the first time an address reaches each referral tier. The tier is decided purely by an address's teamAmount — the sum of stakes made by ev…
Yield Ninja withdraw accounting — AuditVault 19123
withdraw burns shares but fails to debit the corresponding assets.
Zerem unlockExponent handling — AuditVault 20308
The unlock calculation only behaves as intended for exponent one; other exponents leave funds locked.
0x0000…a47b1 MEV Bot Exploit — Unauthenticated `receiveFlashLoan` Drains Idle WETH
Loss · 187.56 WETH (~$245K at the time) — the bot's entire idle WETH balance
The MEV bot at 0x0000…a47b1f is a generalized arbitrage executor. Its entry point is receiveFlashLoan(tokens, amounts, feeAmounts, userData) — the standard Balancer flas…
ATK ("Journey of Awakening") Exploit — Spot-Price `getPrice()` Manipulation via Flash-Loaned Reserve Drain
Loss · ~$127K — attacker drained 44,142,689.6 ATK out of the protocol's reward/dividend contract…
The ATK token exposes an on-chain "price" helper used by the protocol's reward/claim logic:
BabySwap `SwapMining` Exploit — Router-Reported Swap Volume Forged via a Fake Factory
Loss · 24,245.02 USDT (≈ $24.2K) — the BABY mining reward, cashed out into USDT
BabySwap's BabySmartRouter is an aggregation router: the caller passes in their own list of factories, and the router fetches reserves and computes the output amount fro…
BEGO (BGeoToken) Exploit — Signature-Gated `mint()` Bypassed With Empty Signature Arrays
Loss · ~12.04 WBNB (12.037249252714479992 WBNB) drained from the BEGO/WBNB PancakeSwap pair
BGeoToken.mint() is supposed to be a bridge mint: it should only succeed when a quorum of authorized off-chain signers has signed keccak256(bsc, msg.sender, txHash, amou…
Blur — StandardPolicyERC1155 hardcodes matched amount to 1
1. canMatchMakerAsk / canMatchMakerBid return 1 instead of order.amount. 2. BlurExchange uses that amount in _executeTokenTransfer / ERC1155 transfer. 3. Settlement stil…
Carrot Token Exploit — Arbitrary `transReward()` Hijacks the Reward Pool to Bypass `transferFrom` Allowance
Loss · ~$31,318 — 31,318.18 BUSD-T drained from the Carrot/BUSD-T PancakeSwap pair
token (Carrot) ships two fatally-composed bugs:
EFLeverVault Exploit — Direct `flashLoan(0x2)` Inflate-Balance Drain
Loss · ~480 ETH (~$640K at the time). The PoC reproduces 480.006 ETH of profit on the fork; on-c…
EFLeverVault is a leveraged stETH vault: depositors send ETH, the vault takes a Balancer flashloan
HEALTH Token Exploit — Permissionless Per-Transfer Pool-Reserve Burn
Loss · 16.64 WBNB (~$3.7K at the time) net profit to the attacker; the genuine WBNB liquidity of…
HEALTH is a fee/deflation token. Its _transfer() function contains a "drip burn" feature: once a per-pair timer has elapsed, every transfer made by any non-pair address…
HPAY (Hedge Pay) Exploit — Unprotected `setToken()` Lets Anyone Restake Junk and Withdraw Real HPAY
Loss · ~114.43 WBNB drained from the HPAY/WBNB PancakeSwap pair in the simplified PoC (real atta…
The HPAY "bonus" staking contract MintableAutoCompundRelockBonus exposes a public, completely unauthenticated setter:
INUKO / SIG `Bond` Exploit — Flash-Loan LP Mispricing via `balanceOf`-based Valuation
Loss · ≈ $18.4K — attacker walked away with 18,407.05 USDT, having staked only ~5 BNB of seed ca…
The Bond contract lets users lock LP tokens and receive a "SIG" reward (paid in INUKO) whose size is computed on-chain from the current spot value of the deposited LP. T…
Market.xyz / Hundred-clone Exploit — Curve LP Read-Only Reentrancy Inflates Collateral Price
Loss · ~$180k (the PoC ends with 172,389 WMATIC of net flash-loan-funded profit retained before…
Market.xyz (a Fuse/Compound fork) priced its mooCurvestMATIC-MATIC collateral by reading the underlying Curve pool's get_virtual_price(). Curve's NG/crypto-pool remove_l…
Multicall `multicallWithoutCheck()` — Unauthenticated Arbitrary-Call Drain
Loss · 619.748460 USDT drained from the Multicall contract (Polygon PoS USDT, 6 decimals)
The Multicall contract exposes a public, unauthenticated batching entry point, multicallWithoutCheck(Call[] calls) (contracts_Multicall.sol:34-39), that loops over calle…
n00d (SushiBar fork) Exploit — ERC777 Reentrancy via Stale `totalSushi` Share Inflation
Loss · 20.668 WETH drained from the n00d/WETH Uniswap-V2 pair (~$26K at the Oct-2022 ETH price;…
SushiBar is the canonical SushiSwap staking vault (enter/leave) re-deployed for the n00d token. enter() mints staking shares using the formula shares = _amount × totalSh…
OlympusDAO `BondFixedExpiryTeller` Exploit — Unverified Bond-Token in `redeem()` Drains the Teller
Loss · ~$292K — 30,437.077948152 OHM drained from the teller
BondFixedExpiryTeller.redeem(token_, amount_) lets a user redeem a matured bond token for the underlying collateral the teller is custodying. The function accepts the bo…
PLTD Exploit — `_bron` Sell-Accumulator Burns From the Pool, Breaking `x·y = k`
Loss · 24,497.86 USDT (~$24.5K) — the entire honest USDT reserve of the PLTD/USDT pool
PLTD is a "reflection"/fee-on-transfer token. On every sell it silently accumulates a counter _bron equal to 50% of the sold amount (PLTD.sol:419-422). On the next ordin…
Rabby Wallet SwapRouter Exploit — Arbitrary External Call Drains Pre-Approved User Funds
Loss · ~$200,000 across all tokens & victims; the reproduced USDC tranche alone = 46,750.75 USDC…
Rabby Wallet's SwapRouter exposes a public swap() whose dexRouter (call target), dexSpender, and data (calldata) parameters are fully attacker-controlled. Internally the…
RES Token Exploit — Permissionless `thisAToB()` Pool-Reserve Burn Breaks `x·y = k`
UntaggedLoss · ~$290,671 USDT across both attack txs (this single-tx PoC reproduces 195,442.92 USDT of n…
RES is a fee-on-transfer "DeFi" token. Every buy/sell skims a fee, and a slice of that fee is parked in the token contract's own balance (_distSellFee / _distBuyFee → _d…
RES Token Exploit — Self-Burn-From-Pool + `sync()` Breaks the AMM Invariant
Loss · ~$290,671 USDT — drained from the RES/USDT PancakeSwap pair (attacker walked off with 180…
RES is a fee-on-transfer "DeFi" token whose internal _thisAToB() routine sweeps the RES that has accumulated inside the token contract (collected as swap tax), sells it…
RL (RealLand) Exploit — LP-Incentive Airdrop Drained via Reusable LP Position
Loss · 9,078.61 USDT net profit to the attacker (flash-loan funded); ~905,000 RL reward tokens d…
RLLpIncentive.distributeAirdrop(user) pays an LP user a reward proportional to lpToken.balanceOf(user) read live at call time (contracts_demo_RLLpIncentive.sol:65-76). T…
Team Finance Exploit — `migrate()` Burns *Other People's* Locked LP via an Unvalidated `pair` Parameter
Loss · ~$15.8M (multiple tokens): 821.22 ETH + 6,539,633 DAI + 73,168,963,767,872 CAW + 0.0118 T…
Team Finance's LockToken contract held users' Uniswap-V2 LP tokens under time-locks. A migrate() wrapper let a lock owner upgrade their own locked V2 LP into a Uniswap-V…
TempleDAO StaxLPStaking Exploit — Access-Control-Free `migrateStake()` Pool Drain
Loss · ~$2.3M — 321,154.865 xFraxTempleLP tokens drained from the StaxLPStaking pool
StaxLPStaking.migrateStake(address oldStaking, uint256 amount) was designed to let a legitimate staker move their balance from a previous staking contract into this one.…
Transit Finance Exploit — Arbitrary `transferFrom` via Unvalidated Swap Owner
Loss · ~$21M total (across all BSC users who had granted allowance to the ClaimTokens contract);…
Transit Finance's cross-chain swap router lets the caller embed a fully attacker-controlled swap descriptor: the token, the source owner, the destination to, and the amo…
UERII Token Exploit — Public, Unauthenticated `mint()` Inflates Supply and Drains the Liquidity Pool
Loss · ~$2,500 — attacker walked away with 1.8552 WETH swapped from freshly-minted UERII (header…
The UERII token contract exposes a mint() function that is completely public and has no access control: anyone can call it, and each call mints a hard-coded 100000000000…
ULME Token Exploit — Permissionless `buyMiner()` Spends Anyone's Pre-Approved USDT
Loss · ~$250,818 of victim USDT pulled in this replay; the attacker netted +45,734.71 USDT profi…
ULME.buyMiner(address user, uint256 usdt) (UniverseGoldMountain.sol:977-990) is public with no access control and takes the spending account user as a caller-supplied pa…
ULME Token Exploit — Permissionless `buyMiner()` Spends Victims' USDT Allowances
UntaggedLoss · 250,817.77 USDT drained from 100 approved holders; ~50,616.98 USDT net profit to the atta…
The ULME token has a "presale / buy a miner" feature: a holder approves the ULME contract to spend their USDT, then someone calls buyMiner(user, amount) to spend that US…
VTF (Victor the Fortune) Exploit — Compounding Time-Based Mint via Self-Service `updateUserBalance()`
Loss · ≈ 58,419 USDT (58,419.254304386568656998 USDT held by the attacker at the end of the run…
VTF is a deflationary game token with a "hold-to-earn" feature: any address that holds ≥ 100 VTF slowly mints 1% of its own balance per day to itself. That accrual is re…
Xave Finance Exploit — SafeSnap / Reality `DaoModule` Permissionless Governance Takeover
Loss · 100,000,000,000,000 RNBW minted to the attacker (100 trillion tokens, 1e32 wei) + full ow…
Xave attached a SafeSnap / Reality DaoModule to its Gnosis Safe. The intended design: a Snapshot off-chain vote is reflected on-chain as a Reality.eth question; once the…
Bad Guys by RPF Exploit — Unbounded `chosenAmount` in `WhiteListMint()` (Per-Wallet Mint Limit Bypass)
Loss · ~400 NFTs minted in a single tx by one address that should have been capped at 1 — the en…
WhiteListMint(bytes32[] _merkleProof, uint256 chosenAmount) is meant to let each whitelisted address claim one NFT. It enforces "one mint per wallet" with require(_numbe…
BADCODE MEV Bot Exploit — Unauthenticated dYdX `callFunction` Callback Drained to a Max Approval
Loss · 1101.359974579155257683 WETH (≈ $1.45M at the ~$1,320/ETH price of Sep 2022) drained from…
The BADCODE MEV bot implemented dYdX's ICallee.callFunction(address sender, Account.Info accountInfo, bytes data) hook so it could receive dYdX flash-style callbacks. dY…
BNB48 MEV Bot Exploit — Unprotected `pancakeCall` Callback Drains the Bot's Inventory
Loss · ~$144K — the bot's entire token inventory: 25,912.95 USDT + 22,307.55 BUSD + 5,160.32 USD…
A PancakeSwap arbitrage bot exposed a public, unauthenticated pancakeCall(address sender, uint256 amount0, uint256 amount1, bytes data) — the flash-swap callback that a…
BXH Exploit — Spot-Price Bonus Payout Manipulated via Flash-Loan
Loss · ~31,638 USDT net attacker profit (≈40,015 USDT of bonus reserve drained from the staking…
TokenStakingPoolDelegate is a MasterChef-style staking pool. When a pool has enableBonus == true, it pays accrued rewards not in the native reward token (iToken = BXH) b…
DPC (DARK_POOL) Exploit — `claimStakeLp` Self-Compounds the LP Reward Quota (Geometric Doubling)
Loss · Attacker turns 2 BNB → 11.87 WBNB, i.e. +9.87 WBNB net, by minting 279.77 DPC out of thin…
DPC ships a "stake LP, earn an airdrop quota over time" mechanism. The accrued quota is computed by getClaimQuota() (DPC.sol:1246-1279) as
NewFreeDAO (NFD) Exploit — Stateless, Self-Resetting Reward Lets a Borrowed Balance Be Compounded 50×
Loss · ~125M USD headline (4,481 BNB across 3 attack txs). This single reproduced tx (Tx1): +2,9…
The NewFreeDAO "reward" contract (0x8B06…1D1E) pays out NFD tokens proportional to the caller's current NFD balance, gated only by a "collection time" check that is keye…
NXUSD / Nereus Protocol Exploit — LP-Token Oracle Manipulation Drains a Cauldron Lending Market
Loss · ~$371,406 (net flash-loan profit, paid out in native USDC) drained from the NXUSD DegenBo…
The NXUSD market is an Abracadabra/MIM-style CauldronV2 clone running on a DegenBox (BentoBox fork). It lets a user post a Trader Joe USDC/WAVAX LP token as collateral a…
RADT (RADT-DAO / "Dream plan" TWN) Exploit — Permissionless Reward `withdraw()` Drains the LP Pair's Token Reserve
Loss · ~$89,012 — 89,012.35 USDT extracted from the RADT/USDT PancakeSwap pair (net of the 200,0…
TWN (the RADT-DAO token) is a reflection-style token. Every transfer / transferFrom hands control to an external, permissionless reward contract via _wrap.withdraw(from,…
ROI Token Exploit — Missing `onlyOwner` on `transferOwnership` → Reflection-Accounting Mint
Loss · ~157.98 BNB (~$44,000) — gross attacker balance delta in the PoC: +163.33 BNB (5 → 168.33…
ROIToken is a SafeMoon-style "reflection" (RFI) token. Its Ownable.transferOwnership() is missing the onlyOwner modifier (ROIToken.sol:181-185), so anyone can become own…
ShadowFi (SDF) Exploit — Permissionless `burn()` Drains the AMM Pair Reserve
Loss · 1,078.62 WBNB (≈ $300K at the Sept-2022 BNB price) drained from the SDF/WBNB PancakeSwap…
ShadowFi exposes a public, unauthenticated burn(address account, uint256 _amount) (ShadowFi.sol:958-962). It takes an arbitrary account and moves its tokens to the dead…
Thunder Brawl (THB) Exploit — `claimReward()` Reentrancy via ERC-721 Mint Callback
Loss · Reentrant draining of House_Wallet's BNB: the single winning bet of 0.30828 BNB was paid…
House_Wallet.claimReward() (House_Wallet.sol:248-274) pays a winner 2× amount, then mints them a reward NFT, and only after that deletes the win record (delete winners[_…
YYDS Exploit — Spot-Price Oracle Manipulation via Flash-Swap Reserve Draining
Loss · ~$397,942 — 397,942.08 USDT drained from the YYDS/USDT PancakeSwap pair
consumptionReturnPool is a loyalty/cash-back contract that pays users their accrued "return amount" (denominated in USDT) in YYDS tokens. To convert USDT → YYDS it calls…
Zoompro Finance (ZOOM) Exploit — Manipulable FakeUSDT Reserve Skews the Zoom→USD Price
Loss · ≈ 61,160 USDT extracted in a single flash-loan transaction (SlowMist/PeckShield report th…
The "Zoompro / ZOOM" ecosystem prices its $ZOOM token through a PancakeSwap-style pair whose quote asset is FakeUSDT (0x62D51AA…), a token whose supply the attacker can…
ANCH Token Exploit — Reflection Reward Minted on Pair-to-Self `skim()` Transfers
Loss · 526.17 USDT drained from the ANCH/USDT PancakeSwap pair in this single PoC tx (the live c…
ANCHToken is a reflection ("rOwned") token that pays a 0.05% "transaction reward" on every buy and sell larger than minTxnAmount (10,000 ANCH). The reward is minted to t…
Circle / MakerDAO PSM Exploit — Free Vault Closure via a Pre-Authorized CDP
UntaggedLoss · ~$151.67K — 151,669.858678 USDC netted by the attacker
The loss did not come from a contract code bug in MakerDAO core math — it came from a mis-configured, pre-authorized CDP (#28311) under the UNIV2DAIUSDC-A collateral typ…
DDC (BananaSwapToken) Exploit — Permissionless `handleDeductFee()` Pool-Reserve Drain
Loss · ~$104,625 — 104,625.38 USDT drained from the DDC/USDT PancakeSwap pair (attacker spent on…
BananaSwapToken exposes a public, completely unauthenticated function:
EGD Finance Exploit — Flash-Loan Spot-Price Oracle Manipulation Inflates Staking Rewards
Loss · ~$36,044 — attacker walked off with 36,149.42 USDT (≈ the entire EGD token reserve of the…
EGD_Finance is a USDT staking protocol that pays rewards in EGD tokens. A staker accrues a USD-denominated reward "quota" over time; at claim, the contract converts that…
ETN / EtnProduct Exploit — Protocol-Funded Liquidity Sent to the Caller (`addLiquidity → msg.sender`)
Loss · ~$3,074 — net 3,074.53 BUSDT profit; the attacker drained ~606,091 U tokens of protocol-s…
EtnProduct.newProduct() is the protocol's "list a product" function. For every new product it:
LuckyTiger NFT Exploit — Predictable On-Chain "Randomness" in a Pay-to-Win Mint
Loss · NFT mint "bonus pool" drained — attacker mints repeatedly and is refunded 1.9× the mint p…
luckytiger is a "lucky draw" NFT: you pay price = 0.01 ETH to publicMint(), the contract rolls a coin flip, and if you win it pays you back price × 190 / 100 = 0.019 ETH…
MakerDAO UNIV2DAIUSDC CDP Exploit — Free Collateral Withdrawal via a Mis-priced LP-Token Vault (`frob`)
UntaggedLoss · ~$50.5K — 50,562.51 USDC extracted from a single CDP's collateral position
CDP 28311 in MakerDAO's UNIV2DAIUSDC-A ilk was an over-collateralized vault: it held 4.419 UNIV2DAIUSDC LP tokens as ink (collateral) against 9.68M units of art (normali…
Nomad Bridge Exploit — Fraudulent Zero-Root Makes Every Forged Message "Proven"
Loss · ~$152M drained from the Nomad BridgeRouter over hundreds of copy-paste txs. This PoC repr…
Nomad is an optimistic cross-chain messaging bridge. A Replica contract on the destination chain holds a set of trusted Merkle roots; a message is only allowed to execut…
QIXI Token Exploit — Flash-Swap Repaid With a Free-to-Mint / Fee-Skimming Token
Loss · ~6.895 WBNB (≈ the entire WBNB reserve of the QIXI/WBNB pair)
The QIXI/WBNB PancakeSwap pair priced its WBNB against the QIXI token's reported balance. QIXI is a trash ERC20 whose owner can mint an unbounded amount (mmm, Token.sol:…
Reaper Farm Exploit — ERC-4626 `redeem()` / `withdraw()` Missing Allowance Check
Loss · ~$1.7M across all vaults; this PoC drains 12,505.610392 USDC (~$12,505) from a single vic…
ReaperVaultV2 is an ERC-4626-style yield vault. Its public redeem(uint256 shares, address receiver, address owner) and withdraw(uint256 assets, address receiver, address…
XSTABLE.PROTOCOL (XST) Exploit — `skim()`-driven elastic-supply mint that re-inflates the pool's own token reserve
Loss · ~27 WETH net profit in this reproduction (≈ $43K at the Aug-2022 ETH price ~$1.6K); publi…
XStable2 is an elastic-supply ("rebase"-style) token. Its _transfer (XST2.sol:127-165) classifies every transfer into one of three tax regimes by looking at the sender/r…
XSTABLE.PROTOCOL (XST) Exploit — `skim()`-Driven Rebase Mint Inflates Pool Reserves
UntaggedLoss · 27.13 WETH profit to the attacker in this PoC (the historical incident drained the full W…
XST is an "elastic supply" / algorithmic-stablecoin token. Its _transfer (XST2.sol:127-165) applies special accounting whenever a supported pool (the Uniswap pair) is th…
Audius Governance Takeover — Re-callable `initialize()` on Live Proxies via Storage-Slot Collision
Loss · 704.18 ETH (~$1,080,000) — 18,564,497.82 AUDIO drained from the Governance treasury and d…
Audius governance is a set of OpenZeppelin-style upgradeable proxies (AudiusAdminUpgradeabilityProxy) sitting in front of Governance, Staking, and DelegateManagerV2 logi…
FlippazOne Exploit — Missing `onlyOwner` on the Fund-Withdrawal Functions
Loss · The entire ETH balance held by the auction contract. In the forked PoC the contract held…
FlippazOne is a single-NFT (MAX_SUPPLY = 1) English-auction contract. Bidders send ETH via bid(), and that ETH accumulates in the contract's balance until the owner with…
LPC Token Exploit — Self-Transfer Balance Overwrite Mints Free Tokens
Loss · ~178 BNB (≈ $45,715) — drained from the PancakeSwap LPC/USDT pool
LPC._transfer reads the sender's and recipient's balances into separate local variables, then writes them back to storage in two separate statements (LPC.sol:1235-1236):
Omni Protocol Exploit — NFT-Lending Re-Entrancy via `withdrawERC721` / `liquidationERC721`
Loss · ≈ 63.26 ETH net profit to the attacker in this single replayed transaction (the live inci…
Omni was an NFT-collateralised money market (a Paraspace-style fork). When a user withdraws collateral via withdrawERC721, the pool burns the user's nToken and safeTrans…
Quixotic (Optimism NFT Marketplace) Exploit — Unsigned `buyer` Parameter Drains Any Approved ERC-20 Allowance
Loss · 2,667.79 OP drained from one victim that had approved the marketplace (≈ \$2.7K at the ti…
Quixotic's fillSellOrder(...) lets a caller settle a signed NFT sell order as a meta-transaction. The order's authenticity is checked by _validateSellerSignature, which…
SpaceGodzilla Exploit — Permissionless `swapTokensForOther` / `swapAndLiquifyStepv1` Pool-Accounting Drain
Loss · ~$22,516 — 22,516.38 USDT drained from the SpaceGodzilla/USDT PancakeSwap pair (DeFiHackL…
SpaceGodzilla is a "tax + auto-liquify" BSC token whose internal swap/liquify helpers were left public with no access control:
Connext — routers pay signed amount on `execute`, credited only `bridgedAmt` on reconcile
1. Origin xcall swaps adopted → local; only bridgedAmt is messaged. 2. Destination execute (fast path) debits routers from the user-signed _args.amount. 3. _reconcile cr…
Discover / ETHpledge Exploit — Self-Referral Bonus Inflation via Spot-Price-Sourced Reward Math
Loss · The drained reward asset is the Discover token. In the single PoC call, 62,536.76 Discove…
ETHpledge is a yield/referral ("pledge") contract. When a user pledges usdt (BUSD) via pledgein(), the contract rewards the user's upline "inviter" chain with the second…
Gym Network SinglePool Exploit — `depositFromOtherContract()` Mints Stake Without Paying
Loss · 8,000,000 GYMNET drained from the staking pool's own token reserves (≈ $1.5–1.9M; GYMNET…
GymSinglePool.depositFromOtherContract() is a permissionless entry point (contracts_GymSinglePool.sol:286-294) that records a staking deposit without ever pulling the de…
Harmony Horizon Bridge Exploit — Compromised 2-of-5 Multisig Drains the Ethereum-Side Manager
Loss · Total bridge drain ≈ $100M across many tokens/txs; this PoC reproduces a single USDT leg…
The Harmony Horizon Bridge guarded its Ethereum-side custody (ERC20EthManager) with a MultiSigWallet configured to require only 2 confirmations out of its owner set (2-o…
Inverse Finance Exploit — Spot-Balance Oracle Manipulation of the `yvCurve-3Crypto` Price Feed
Loss · ~$1.26M to Inverse Finance (≈53.24 WBTC profit to the attacker in this fork; the original…
Inverse Finance's "Frontier" money market (a Compound v2 fork) priced the yvCurve-3Crypto collateral token with a custom feed, YVCrv3CryptoFeed. To value the underlying…
Optimism (Wintermute) Exploit — Uninitialized Gnosis Safe Proxy Front-Run
Loss · 20,000,000 OP tokens (the market-making grant Wintermute had sent to the proxy). Wintermu…
1. Wintermute deployed a Gnosis Safe Proxy on the freshly-launched Optimism L2 to hold the 20M OP market-making grant, but the L1→L2 message that was supposed to call se…
Putty — acceptCounterOffer may result in both orders being filled
Untagged1. acceptCounterOffer cancels originalOrder then fills the counter order. 2. cancel() does not revert if the order was already filled. 3. Frontrunner fills original firs…
Snood (Schnoodle) Exploit — `transferFrom` Allowance Bypass Drains the SNOOD/WETH Uniswap Pair
Loss · ~104.047 WETH (104,047,009,087,796,436,864 wei) — the entire WETH reserve of the SNOOD/WE…
1. SNOOD is an ERC-777-derived token that layers a "reflection" mechanism (a la a t-token) over OpenZeppelin's ERC777Upgradeable. The reflection rate is applied to the r…
XCarnival Exploit — Untrusted `xToken` Argument in `pledgeAndBorrow` Lets Orders Borrow Against Already-Withdrawn Collateral
Loss · ~3,087 ETH (~$3.87M) in the live attack (PeckShield/BlockSec figure). The bundled PoC rep…
XCarnival was an NFT-collateral lending protocol: a user pledges an NFT into XNFT and borrows ETH against it from an XToken lending pool, with P2Controller enforcing an…
BAYC / ApeCoin Airdrop Exploit — ERC-3156 Flash-Loan of Vaulted BAYC to Steal the APE Claim
Loss · 60,564 APE (60,564,000,000,000,000,000,000 wei) — the ApeCoin airdrop entitlement for 6 B…
1. The ApeCoin airdrop contract AirdropGrapesToken.claimTokens() grants APE to any address that currently owns BAYC (beta) NFTs, computing the payout from a live beta.ba…
FactoryDAO — Blacklisted user may permanently block `withdrawExcessRewards`
Untagged1. withdraw AND-chains every ERC20 transfer and reverts if any fails. 2. A blacklisted (or paused-token) user can never clear their deposit. 3. withdrawExcessRewards req…
Fortress Loans Exploit — Governance Capture + Poisoned Umbrella Oracle → Over-borrow
Loss · ~3,000,000 USD — 1,048 ETH + 400,000 DAI drained on mainnet (BSC-side extraction left the…
Fortress Loans is a Compound-V2 fork whose GovernorAlpha could be captured with a tiny FTS stake (proposal threshold 100,000 FTS = 1% of supply, quorum 400,000 FTS = 4%)…
HackDao Exploit — Fee-on-Transfer Token Listed in a Vanilla Pancake Pair (skim/sync reserve desync)
Loss · 163.673482526496579211 WBNB drained from the HackDao/WBNB Pancake pair (the attacker flas…
1. Hackerdao is an ERC-20 with a heavy transfer-fee regime baked into its overridden _transfer (Token.sol#L457-L521). Every non-whitelisted transfer pays a 12% fee, a 4%…
NOVO Exploit — `transferFrom` Skips Allowance Check, Pool Reserve Drained
Loss · ~248.124 WBNB (net profit) — the attacker started with 10 WBNB and ended with 258.1241393…
NOVO is a reflection/anti-whale BEP20 listed in a vanilla PancakeSwap NOVO/WBNB pair. Its transferFrom(sender, recipient, amount) overrides the inherited ERC20 but, in a…
Aku-Auction (Akutar NFT) Exploit — Push-Payment Refund DoS & Permanently Locked Funds
Loss · Bidder ETH permanently locked in the Aku/Akutar auction contract (AkuAuction.balance). No…
AkuAuction is a descending-price ("Dutch"-style) NFT dutch auction for the Akutar collection. Users bid ETH at the current getPrice() and are tracked in an allBids[] arr…
Beanstalk Farms Exploit — Flash-Loan Governance Self-Pass
Loss · ~$182M (non-Bean assets: USDC, USDT, DAI, 3Crv, etc.) drained after the attacker passed a…
Beanstalk's governance let any Bean depositor vote on Beanstalk Improvement Proposals (BIPs) with voting weight equal to their Stalk (deposit). Critically:
CFToken Exploit — Exposed `public _transfer` Lets Anyone Drain the Pair's Tokens
Loss · The PoC pulls 1,000 CF (1e21 raw, 18-decimals) directly out of the PancakeSwap pair in a…
1. CFToken implements its own BEP-20. The internal balance-moving helper _transfer(address from, address to, uint256 amount) — the function that does _tOwned[from] -= am…
DEUS Finance DEI Exploit — Privileged `Swapin` Mint + DEI Collateral/LP Mispricing
Loss · ~$1.3M — attacker mints 150,000,000 USDC (6-dec) out of nothing, converts it through the…
fUSDC (DEUS's Fantom USDC) exposes a privileged mint entry point Swapin(bytes txhash, address to, uint256 amount) that lets the owner mint arbitrary USDC to any address.…
Elephant Money Exploit — Infinite Mint via the Unverified Trunk Router (`mint`/`redeem` Accounting Flaw + Elephant Buy-Back Feedback)
Loss · ~$11M (April 2022, BSC). The PoC below extracts 5,892,847 BUSD of net profit from a singl…
1. Elephant Money runs a "stable" token called Trunk (ElephantDollar). You mint Trunk by calling not_verified.mint(bUSDAmount) on the router 0xD520a3B47E42…, which pulls…
Gym Network `LiquidityMigrationV2` Exploit — Migration Contract Spends Its Own `GYMNET` to Mint LP for the Caller
Loss · ~$2.1M — the PoC recovers 1,373,564,008,267,780,664,495 wei ≈ 1,373.56 WBNB (After exploi…
LiquidityMigrationV2 (contracts_LpMigration.sol:31-90) was a one-shot migrator: an old WBNB/GYM LP holder calls migrate(lpTokens), the contract burns their old LP and re…
Rari Capital / Fei Protocol Fuse Exploit — Mis-Configured Collateral Oracle (USDC Priced Off the ETH/USD Chainlink Feed)
Loss · ~$80M total across the exploited Fuse pools (documented industry figure for the Apr 30 20…
Rari Fuse was a permissionless Compound fork: anyone could spin up an isolated lending "pool", and each pool's Comptroller priced every listed cToken's underlying throug…
Rikkei Finance Exploit — Permissionless `setOracleData()` Oracle Hijack on a Compound-style Money Market
Loss · ~$270K — 346,199.780826500224370302 rUSDC (~346,199.78 USDC) drained from the rUSDC marke…
1. Rikkei Finance is a Compound V1 fork on BSC. Its Cointroller (risk engine) prices every market's collateral through a single SimplePriceOracle, which resolves each rT…
Saddle Finance sUSD MetaPool Exploit — Virtual-Price Manipulation Round-Trip
Loss · On-chain attack: ~$10M (multiple sUSD-metapool pools drained, Apr 30 2022). This reproduc…
1. Saddle's sUSD V2 "metapool" is a 2-token StableSwap pool whose two pooled tokens are sUSD and saddleUSDV2 (an LP token). That LP token itself represents a pro-rata cl…
WDOGE (Wrapped Doge on BSC) Exploit — Reserves-Out-of-Sync Drain via Repeated `skim`/`sync`
Loss · ~8 WBNB profit per cycle (the PoC extracts 2,978,658,352,619,485,704,640 wei ≈ 2,978 WBNB…
The attacker flash-swaps 2,900 WBNB from the WBNB/BUSD pair, then walks it through the WDOGE/WBNB pair in a deliberate sequence of transfer→swap→transfer→skim→sync→swap:
Zeed Finance Exploit — Reward-Fee Tri-Crediting Inflates YEED Pair Balances, Skim-Loop Drains USDT
Loss · ~112,446.89 USDT (112,446,885,258,969,301,193,152 wei, 18-dec USDT) drained from Zeed's Y…
1. YEED is a PancakeSwap-listed ERC20 that, on every sell-side transfer into a registered swap pair, deducts a _rewardFee of 50 / 1000 = 5% and a _burnFee of 50 / 1000 =…
Agave Finance Exploit — Reentrancy in `liquidationCall` (Aave-v2 fork)
Loss · ~$1.5M (WETH, agVE, and other reserves drained from the Gnosis Chain lending pool)
Agave was a near-verbatim fork of Aave v2. The Aave v2 GenericLogic / liquidationCall path was later found to have a reentrancy window where the collateral is transferre…
API3 dAPI median can be moved by one compromised report
For three values, the median is the middle ordered value. If two honest oracles report 598 and 603, a compromised third oracle can report 598, 601, 603, or any value in…
Auctus (ACO) Exploit — `ACOWriter` Trusts Attacker-Supplied `acoToken` + Arbitrary `exchange` Call
Loss · ~$682K USDC pulled from the ACO protocol's collateral/escrow holder (0xCB32…993B)
Attacker passes itself as acoToken (implements minimal IACOToken surface):
Bacon Protocol Exploit — Reentrancy via ERC-1820 `tokensReceived` in `lend`/`redeem`
Loss · ~$1M USDC (the test extracts 957,786,585,605 = ~$957.8K USDC)
Bacon's pool token (IBacon) and USDC are wired through the ERC-1820 registry: when USDC is transferred, a registered tokensReceived hook fires on the recipient. The atta…
Compound cTUSD `sweepToken` Exploit — Comptroller Swap to Compliant TrueUSD
Loss · 39,961,358,379,339,258,374,306,712 (~$40M worth) of legacy TrueUSD swept out of the cTUSD…
sweepToken(ERC20 token) is a Compound cToken helper meant to rescue tokens accidentally sent to a cToken contract, sending them to the Comptroller/admin. On the cTUSD ma…
Fantasm Finance Exploit — Decimal Miscalculation in `mint` Over-issues xFTM
Loss · The PoC turns 100 FSM into 27,808,380,491,957,617,661,247 xFTM (~27,808 xFTM) via a decim…
The attacker (pranked as a holder of 100 FSM) calls:
Hundred Finance Exploit — ERC-667 Reentrancy in `borrow`/`redeem` (Compound fork)
Loss · The PoC extracts ~$42,994,684 (43.0e6) USDC; the live incident drained the hUSDC market.
Hundred Finance was a Compound-v2 fork whose cToken markets wrapped/interacted with ERC-677-style tokens (transferAndCall / onTokenTransfer callbacks, notably the G-nati…
LiFi Exploit — Unvalidated `callTo`/`approveTo` in the Pre-Bridge Swap Facet
Loss · Part of the ~$5.7M drained across many victims in the March 20, 2022 LiFi incident; this…
1. LiFi is a cross-chain bridge aggregator. Its diamond exposes swapAndStartBridgeTokensViaCBridge(LiFiData, SwapData[], CBridgeData): before bridging, it walks an array…
OneRing Finance Exploit — Missing Reentrancy Guard + Under-priced `depositSafe`
Loss · ~$1.45M USDC (the PoC extracts 1,526,751,528,201 = ~1.526M USDC)
OneRing's vault priced shares from a "strategy total value" oracle rounded/computed per-epoch. The depositSafe/withdraw pair had no reentrancy lock, so within a single f…
Paraluni MasterChef Exploit — Reentrancy in `depositByAddLiquidity` via Malicious Token
Loss · ~$1.7M (USDT + BUSD drained from Paraluni MasterChef pools)
The attacker deploys an EvilToken whose transferFrom is hooked: whenever MasterChef pulls it during depositByAddLiquidity, EvilToken.transferFrom calls back into MasterC…
Redacted Cartel (wxBTRFLY) Exploit — Faulty `transferFrom` Allowance Logic
Loss · Allowance hijack — an attacker can assign a victim's allowance to themselves and steal th…
wxBTRFLY implemented a custom transferFrom/approval path with "operator" semantics that did not match standard ERC20. As the PoC header states:
Revest Finance Exploit — Reentrancy in FNFT `mintAddressLock`/`withdraw`
Loss · The PoC extracts 352,835,865,880,437,990,126,099 RENA (~$2M at the time)
Revest lets you lock tokens inside an ERC-1155 "FNFT" with an address-lock condition. The mint and withdraw flows call back into the lock-creator/recipient contract (via…
Ronin Bridge Exploit — Sky Mavis Validator Key Compromise (Forged Withdrawals)
Loss · ~$625M (173,600 WETH + 25.5M USDC) — the largest DeFi hack at the time
The Ronin bridge's withdrawERC20For(withdrawalId, user, token, amount, signatures) releases locked assets on Ethereum once a quorum of validator signatures over the requ…
TreasureDAO Marketplace Exploit — Zero-Quantity Buy Drains Listed NFTs for Free (`_pricePerItem * _quantity` with `_quantity = 0`)
Loss · NFT theft — listed SmolBrain #3557 bought for 0 MAGIC (the buyer router pulled pricePerIt…
The TreasureDAO marketplace is split across two contracts: an inner TreasureMarketplace (0x2E3b85F8…) that holds listings and actually moves NFTs, and a public, user-fac…
Umbrella Network RewardPool Exploit — Integer Underflow in `withdraw`
Loss · ~$700K (UniLP tokens drained from the Umbrella reward/staking pool)
The vulnerable code (quoted in the PoC):
Build Finance (BUILD) Exploit — Governance Takeover via Low Quorum → Arbitrary-Proposal Drain
Loss · Treasury drain of the Build Governance contract's BUILD holdings — 329,224.64 BUILD were…
1. Governance is a GovernorAlpha-style contract that custodies BUILD tokens: every propose/vote pulls the caller's entire BUILD balance into the Governance contract via…
Foundation — Creators can steal sale revenue from owners' sales
Untagged1. Secondary sales should pay ~10% royalty to creators and the rest to the seller. 2. If getRoyalties lists the seller as a recipient, the market treats the sale as a cr…
Meter.io Exploit — AnyswapV3ERC20 `transferWithPermit` Guard Logic Flaw
Loss · ~$1M WETH-equivalent (wETH on Moonriver drained from the bridge)
AnyswapV5ERC20.transferWithPermit (AnyswapV5ERC20.sol:484-508) is a gas-saving "permit + transfer in one call" — a holder signs a message authorising moving value from t…
TecraSpace (TCR) Exploit — Swapped Allowance Keys in `burnFrom`
Loss · 639,222 USDT (~$639K)
TcrToken.burnFrom (TcrToken.sol:154-159) checks the wrong side of the allowance mapping:
The Sandbox LAND Exploit — Public `_burn` of Anyone's NFT
Loss · Asset destruction / griefing (LAND NFTs of arbitrary users burned)
The Sandbox Land contract exposed what should have been an internal ERC721 helper as a public function with no access control. _burn(address from, address owner, uint256…
Anyswap (Multichain V4 Router) Exploit — Underlying-Transfer Cross-Chain Drain
Loss · ~$8M (WETH) across the incident; the cross-chain burn path was weaponized
anySwapOutUnderlyingWithPermit (AnyswapV4Router.sol:261-277) implements an "out with underlying" cross-chain swap in three steps:
Basis MultiDistributor — unprotected minimum-distribution list growth
setMinimumDistribution is documented for trusted participants, but anyone can append token addresses. Repeated zero-minimum entries inflate every distribution loop and c…
Behodler — Double transfer in ERC677 `transferAndCall`
UntaggedtransferAndCall calls super.transfer and then _transfer again for the same _value, so the sender is debited twice and the receiver is credited twice.
Behodler / LimboDAO — `assertGovernanceApproved` has no access control (anyone can lock a user's funds)
Notional — malicious treasury manager can burn treasury tokens via makerFee
Untagged1. Treasury manager signs 0x orders to sell harvested COMP for WETH. 2. _validateOrder never requires makerFee == 0 and takerFee == 0. 3. Malicious manager sets makerFee…
Origin — arbitrary ERC20 can block offer finalization
Offers store any ERC20 address. A malicious token that always reverts on transfer is called during finalization, permanently blocking settlement without an alternate rev…
Origin — listing deposit can be withdrawn repeatedly
withdrawListing authorizes the deposit manager but never marks the listing withdrawn. The same deposit can be transferred six times, draining the marketplace reserve.
OriginToken migration leaves V00 Marketplace escrow on the paused token
Loss · A 10 OGN listing deposit and a 20 OGN offer (30 OGN total) remain escrowed in the Marketp…
Qubit Finance QBridge Exploit — Zero-Address Token Whitelist Bypass
Loss · ~$80M (the largest Qubit incident; bridge minted unbacked assets on BSC)
QBridgeHandler.deposit (QBridgeHandler.sol:122-137) looks up the token for a resourceID:
Grim Finance Exploit — Reentrant `depositFor()` Share Inflation in the GrimBoost Vault
Loss · 362,770.6 WFTM + 11.78 anyBTC extracted from the GrimBoost vault / SpiritSwap pool (~$1.3…
GrimBoostVault.depositFor(address token, uint256 _amount, address user) mints vault shares using the classic Beefy/yVault formula
Kuiper — stale fee checkpoint after `totalSupply` reaches zero
Loss · Extra fee tokens are minted after a zero-supply interval, diluting basket holders' underl…
handleFees() returns immediately when totalSupply == 0 without advancing lastFee. After all holders burn, the first resupply leaves the old timestamp intact; the next mi…
Nerve Bridge (Saddle/MetaSwap) Exploit — Stale `baseVirtualPrice` Cache Lets a Round-Trip Mint Free fUSD
Loss · ~39,052 BUSD net profit per attack run (flash-loaned, so ~100% margin); the real-world Ne…
Nerve's MetaSwap is a Saddle-style metapool: it pools the meta token fUSD against the LP token of a base StableSwap pool (nerve3LP, the receipt for the BUSD/USDT/USDC ne…
Visor Finance (vVISR) Exploit — Free Share Minting via Attacker-Controlled `delegatedTransferERC20`
Loss · ~$8.2M — ≈ 8.8M VISR drained from the RewardsHypervisor (VISR collapsed ~90%+ after the h…
RewardsHypervisor.deposit(visrDeposit, from, to) mints vVISR shares to to proportional to a claimed visrDeposit, but never verifies that the VISR was actually received.…
MonoX Finance Exploit — Self-Swap Price Inflation (`swapExactTokenForToken(MONO, MONO)`)
Loss · ~$31M total in the live hack; this single-pool PoC extracts 4,000,000 USDC (the cap the P…
MonoX is a single-sided AMM: instead of paired reserves, every token gets its own pool whose value is measured against a virtual stablecoin, vCASH. Each pool stores a pr…
Ploutoz / Dollar Online (DOP) Exploit — Spot-Price Oracle Manipulation Against a bZx/Fulcrum-Fork Lending Pool
Loss · ~330,710 BUSD profit to the attacker (DeFiHackLabs header lists ~$365K of assets drained)…
The Ploutoz lending pools are a fork of bZx/Fulcrum. Each pToken pool lets a user post DOP as collateral and borrow an underlying asset (CAKE, DOLLY, WETH, BTCB, USDT, B…
Streaming — arbitraryCall lets compromised gov drain user allowances
After an incentive is claimed, incentives[token]==0 so compromised governance can arbitraryCall the token with transferFrom and steal leftover allowances
Streaming — recoverTokens broken after creatorClaimSoldTokens (isSale)
creatorClaimSoldTokens does not update redeemedDepositTokens, so recoverTokens underflows and excess deposit tokens are permanently locked
Streaming — recoverTokens steals rewards when depositToken == rewardToken
When deposit and reward tokens are the same, recoverTokens' deposit excess formula includes the reward inventory and the creator drains user rewards
Vader Protocol — TWAP decimal-count price collapse causes USDV over-minting
The oracle receives a ratio and has to express it in the quoted token's smallest units. For an 18-decimal token, that requires multiplying by 10 18. The audited code mul…
VaderPoolV2 `mintFungible` steals a victim's deposit to an attacker (arbitrary `from`)
VaderPoolV2 `mintSynth` mints a victim's deposit to an attacker (arbitrary `from`)
VaderPoolV2 synth redemption priced off manipulable spot reserves drains the pool
Cream Finance (Oct 2021) Exploit — yUSD `pricePerShare` Donation-Inflation → Over-Collateralized Borrow
Loss · ~$130M drained from Cream Finance lending markets (largest DeFi hack of 2021 at the time)
Cream priced its crYUSD collateral market by reading the yUSD Yearn-vault pricePerShare() (multiplied by the underlying Curve pool's get_virtual_price). pricePerShare is…
Indexed Finance Exploit — `reindexPool` + `updateMinimumBalance` Index-Token Mint/Redeem Manipulation
Loss · ~$36M of underlying tokens drained from two index pools (DEFI5 + CC10). The PoC reproduce…
Indexed Finance index pools (DEFI5, CC10) are Balancer-V2-fork AMMs where the desired token weights are set by an external MarketCapSqrtController from a Uniswap-TWAP ma…
DAO Maker Exploit — Unprotected `init()` Re-initialization → `emergencyExit` Vesting Drain
Loss · 5,760,000 DERC (DeRace Token) swept from the 0x2fd6... clone. Across the campaign (4 clon…
DAO Maker deployed many minimal-proxy ("clone") vesting contracts, one per token sale / SHO allocation. Each clone is configured after deployment by an external init(...…
Liquity — zero-ICR reinsertion strands a trove
SortedTroves removes a node and only reinserts it for a positive ICR. A zero-ICR update leaves TroveManager's existence belief inconsistent, so addCollateral and other c…
MISO / SushiSwap Dutch Auction — `batch()` `delegatecall` Reuses `msg.value`
Loss · 400 ETH drained from the live DutchAuction at fork block 13,038,771 (100 ETH committed →…
DutchAuction inherits BoringBatchable, which exposes a public, payable batch(bytes[] calls, bool revertOnFail) that executes each supplied calldata via address(this).del…
Nimbus Pair Exploit — Broken `K`-Invariant Check (10000 vs 1000 Scaling Bug)
Loss · 73.60 USDT drained from the USDT/NBU Nimbus pair in a single swap(). The same primitive i…
NimbusPair is a Uniswap-V2 fork. Uniswap's swap() enforces the constant-product invariant with a 0.3% fee by scaling balances by 1000 and reserves by 1000²:
NowSwap / Nimbus Exploit — Broken `k`-Invariant via a `10000` vs `1000` Scaling Mismatch
Loss · ~6,247.5 NBU drained from the NWETH/NBU pair in a single swap (the pool's NBU side was re…
NimbusPair is a Uniswap-V2 fork. Its swap() function ends with the usual "did k stay big enough?" guard, but the two sides of that inequality are scaled by different pow…
ZABU Finance Exploit — MasterChef Reward Inflation via Fee-on-Transfer `lpSupply` Collapse
Loss · 4,526,636,431 ZABU drained from the farm, dumped for +1,089.39 WAVAX net profit (≈ $70K a…
ZABU Finance ran a standard SushiSwap-style MasterChef farm. For each pool, the per-share reward accumulator is updated as
Cream Finance / AMP Exploit — Cross-Market Reentrancy via ERC777 `tokensReceived`
Loss · ~$18.8M (≈ 462,079,976 AMP + 2,875.62 ETH)
CREAM Finance is a Compound v2 fork. In CToken.borrowFresh, the protocol sends the borrowed asset to the borrower before it records the new debt in storage:
Poly Network Exploit — Function-Selector Collision Hijacks the Cross-Chain Keeper Public Key
Loss · One of the largest hacks in DeFi history — ~$610M total across Ethereum, BSC and Polygon.…
Poly Network's EthCrossChainManager (ECCM) is a privileged dispatcher: anyone may submit a "proof" of a transaction that supposedly happened on another chain, and verify…
Popsicle Finance (Sorbetto Fragola) Exploit — LP-Token Transfer Skips Reward-Debt Sync
Loss · ~$20.7M across 8 vaults — e.g. 2,101,236.92 USDT + 2,203,367.84 USDC + 1,318.94 WETH + 48…
SorbettoFragola is a Uniswap-V3 liquidity-manager vault. It mints an ERC20 receipt token ("PLP") for depositors and tracks each user's claimable trading fees with a Mast…
Wault Finance Exploit — WUSDMaster `redeem()` Pro-Rata WEX Drain via Self-Manipulated WEX Price
Loss · ~117,670 BUSD captured in the reproduced PoC (≈ the entire WEX reserve of the WUSDMaster…
WUSDMaster is Wault Finance's stablecoin manager. Users stake() USDT to mint WUSD 1:1; on each stake the contract diverts a fixed 10% (wexPermille = 100) of the deposite…
XSURGE (Surge) Exploit — Reentrancy on a Liquidity-less Bonding-Curve Token
Loss · ~$2.56M at the time — the SurgeToken contract's entire ~4,210 BNB reserve was drained, an…
SurgeToken is a "liquidity-less" token: it has no AMM pool. Instead, the contract holds BNB directly and acts as its own bonding-curve "DEX" — send BNB and it mints you…
ChainSwap Exploit — Self-Signed `receive()` Cross-Chain Mint (Forgeable Validator Set)
UntaggedLoss · ~$8M across many bridged tokens (this PoC replays one receive() call minting 19,392.28 un…
ChainSwap is a cross-chain bridge. On the destination chain, tokens are released to a user by calling MappingBase.receive(fromChainId, to, nonce, volume, signatures) (To…
ChainSwap Exploit (BSC) — Self-Signed `receive()` Cross-Chain Mint (Forgeable Validator Set)
UntaggedLoss · ~$8M across both chains and dozens of bridged tokens. This BSC PoC replays one receive()…
ChainSwap is a cross-chain bridge. On the destination chain, tokens are released to a user by calling MappingBase.receive(fromChainId, to, nonce, volume, signatures) (Fa…
Levyathan Finance Exploit — Leaked Deployer Key → Timelock-Gated Ownership Hijack → Unlimited `mint()`
Loss · ~$1.5M (rekt) — attacker minted 100,000,000 LEV (≈6.1× the entire prior supply) and dumpe…
Levyathan's LEVToken is a standard Ownable ERC20 whose owner is the only address that can mint() (LEVToken.sol:33-35). That owner is the MasterChef contract, which in tu…
88mph NFT Exploit — Unprotected `init()` Lets Anyone Seize Ownership of a Live NFT Clone
Loss · No direct fund loss in this PoC; the bug grants full control of a deployed NFT contract (…
88mph mints ERC721 "receipt" NFTs from a CloneFactory. Each NFT is an EIP-1167 minimal-proxy clone of a single NFT template. Because clones have no constructor, the temp…
Base/reward token alias inflates `burnForBase` — reward-accounting theft
Loss · Burners receive reward funding as if it were base principal
burnForBase pro-rates the entire base-token balance. If rewards use the same token as base, reward funding is counted as principal and a burner receives 150 for 100 stra…
Eleven Finance Exploit — `emergencyBurn()` Pays Out Underlying Without Burning Vault Shares
Loss · ~$647.5K — 647,573.87 BUSD net profit drained from other vault depositors
ElevenNeverSellVault is a yield-aggregator vault: deposit cake_LP (NRV/BUSD PancakeSwap LP), receive 11nrvbusd vault shares 1:1; the vault stakes your LP in Nerve's Mast…
Non-existent module delegatecall appears successful — unchecked target
Loss · Batches silently skip a module call and continue with stale state
delegatecall to an EOA or destroyed contract returns true. Ladle's module registry can therefore mark a no-code address as valid and report a successful module execution…
PancakeHunny Exploit — `mintFor()` Reward Inflation via `balanceOf(this)` Donation
Loss · ~$700K–$1M drained from PancakeHunny vaults in the live incident (this replay demonstrate…
HunnyMinter.mintFor() is the routine every PancakeHunny vault calls to (a) zap the harvested performance fee into a HUNNY-BNB LP position for the staking pool and (b) mi…
Payable delegatecall loop reuses `msg.value` — value-accounting hazard
Loss · Future value-sensitive logic can count one payment multiple times
Every delegatecall in a payable batch inherits the original msg.value. The reduction calls a hypothetical value-sensitive credit() twice and records two ether of credit…
SafeDollar (SDO) Exploit — MasterChef Reward Inflation via Drained `lpSupply` Divisor
Loss · 188,156.50 USDC drained from the SDO/USDC pool (≈ the entire stablecoin peg backing). The…
SdoRewardPool is a SushiSwap-MasterChef fork that mints SDO as a farming reward. For each pool it computes accSdoPerShare += sdoReward * 1e18 / lpSupply, where lpSupply…
Unbatched `startPool` can be front-run — initial mint theft
Loss · An honest LP's preloaded base is minted to a front-runner
If liquidity is transferred to the Strategy before the router's batch reaches startPool, an attacker can front-run that call and receive the entire initial strategy-toke…
xWin Finance Exploit — Disabled Slippage Control + `_tradeParams.amount`-Based Reward Inflation
Loss · 842.49 BNB of net profit to the attacker (≈ $176K at the June-2021 BNB price), funded by…
xWin pays an XWIN-token farming reward proportional to how much BNB a user deposits ("subscribes" to a fund). The reward is booked against _tradeParams.amount — the BNB…
Yield V2 Witch `buy`/`payAll` accepted vaults that were not under auction
bEarn / bVaults BUSD-Alpaca Strategy Exploit — `emergencyWithdraw` Re-prices Shares Against a Self-Inflating `wantLockedTotal`
Loss · 123,089.10 BUSD (~$123K) extracted from the bVaults BUSD-Alpaca strategy in a single tran…
BvaultsBank.emergencyWithdraw() pays a user amount = user.shares × wantLockedTotal / sharesTotal, reading the strategy's current wantLockedTotal and sharesTotal (Bvaults…
BurgerSwap (Demax) Exploit — Re-entrant Multi-Hop Swap Drains the WBNB Side of the Pool Twice
Loss · ~$3.2M — attacker walked off with 110,564 BURGER + 2,398 WBNB (net) after repaying a 6,06…
BurgerSwap's DemaxPlatform router executes a multi-hop swap in two distinct phases:
JulSwap (JulProtocolV2) Exploit — Spot-Price Manipulation of `addBNB()` Liquidity Provisioning
Loss · 522.84 WBNB drained in the reproduced tx (~$155K–$190K @ ~$300–370/BNB late-May-2021). De…
JulProtocolV2.addBNB() is a "yield deposit": a user sends BNB, and the protocol pairs the user's BNB with the protocol's own JULb inventory to add liquidity to the JULb/…
PancakeBunny Exploit — Flash-Loan LP Price-Oracle Manipulation Mints Unlimited BUNNY
Loss · ~$45M at the time — attacker walked away with ≈49,353.77 WBNB + 3,810,822.52 USDT profit…
PancakeBunny's VaultFlipToFlip pays its yield in the protocol's own BUNNY governance token. The number of BUNNY minted to a depositor is computed by asking the protocol'…
Rari Capital ETH Pool Exploit — `ibETH.totalETH()` Accounting Reentrancy via `Bank.work()`
Loss · +32.32 ETH to the attacker in a single tx (the live campaign drained Rari's ETH pool for…
Alpha Homora's ibETH Bank is an ERC20 "interest-bearing ETH" share token. Its per-share value is derived from totalETH() = address(this).balance + glbDebtVal − reservePo…
Spartan Protocol Exploit — LP-Share Inflation via Spot-Balance Accounting + Unsynced Donation
Loss · ~$30.5M (≈ 29,604 WBNB drained over ~8 repeated cycles). The extracted single-cycle PoC r…
Spartan's Pool keeps two notions of its holdings:
Value DeFi vSafe WBNB Vault — Inflated-Share Mint via Manipulated Alpaca `ibBNB` Strategy Price
Loss · attacker minted 396.17 vSafeWBNB shares for a 273.81 WBNB net deposit — a ~44% over-issue…
VSafeVaultWBNB is a yield vault that mints shares to depositors in proportion to deposit / pricePerShare, where the share price is derived from the vault's total holding…
Uranium Finance Exploit — Broken Constant-Product `K` Check (100× Slack in `swap()`)
Loss · ~$50M total across all pairs. This PoC drains a single WBNB/BUSD pair for 8,593,840 BUSD…
Uranium Finance forked Uniswap V2 / PancakeSwap and lowered the swap fee from 0.30% to 0.16%. To do this they changed the fee constant in UraniumPair.swap() from 1000 to…
DODO DVM Flashloan Exploit — Unprotected `init()` Reinterprets Pool Reserves
Loss · ~$1,140,965 — 1,140,965.86 USDT drained from one wCRES/USDT DVM pool (the campaign hit se…
DODO V2's DVM (Vending Machine) pool exposes init(...) as an external function with no access control and no "already initialized" guard. init overwrites _BASE_TOKEN_, _…
PAID Network Exploit — Compromised Upgrade/Owner Key → Unlimited `mint()`
Loss · ~$3M realized (≈$160M of PAID minted then dumped; market dump capped recovery). The PoC p…
PAID's ERC20 implementation exposes an owner-only mint(address, uint256) with no maximum supply, no per-call cap, and no timelock. On 2021-03-07 an attacker who controll…
Pool accepts input when output token has no code — silent transfer failure
Loss · A swapper loses input tokens without receiving output
Solidity low-level calls to an account with no code return success. The pool therefore accepts 1,000 input tokens while its “output token” call to a non-deployed address…
Yearn yDAI v1 Exploit — Curve-Backed Vault Share-Price Manipulation
Loss · ~$11M (Yearn-disclosed). Single-pass net extracted in the PoC: 349,852 3Crv + 185,137 USD…
The yDAI v1 vault does not custody DAI directly — it forwards deposits, via a Controller, to StrategyDAI3pool, which converts the DAI into Curve 3pool LP tokens (3Crv) a…
OUSD can transfer more than the displayed balance — rounding/precision loss
Loss · A holder can transfer one token more than balanceOf reports
Rebasing credits can make the token-facing balance larger than the credit deduction for a transfer. Flooring creditsDeducted before validating the token amount lets a th…
OUSD total supply can fall below user balances — broken rebasing invariant
Loss · ERC-20 supply accounting becomes inconsistent and can understate claims
An opted-out account keeps its balance while changeSupply lowers the aggregate total. The common balanceOf(x) <= totalSupply() invariant is immediately false.
Reentrant `mintMultiple` callback — untrusted external call
Loss · Reentrant asset callback can mutate vault accounting before mint completion
mintMultiple computes state and then calls every caller-supplied asset. A malicious token's transferFrom callback re-enters mint, proving that the no-guard ordering expo…
SushiMaker — Bridgeless `convert()` Lets an Attacker Insert a Fake Pair and Steal Onsen Fee Liquidity (Badger DIGG)
Loss · ~81 WBTC + DIGG of accumulated Onsen LP fees siphoned from the SushiMaker (≈ low-hundreds…
SushiMaker.convert(token0, token1) (:85) takes the LP tokens the SushiMaker has accrued as protocol fees for a given pair, burns them to get the two underlying tokens, a…
Timelock.admin takeover through a regular proposal — governance privilege escalation
Loss · Governance administration can be seized by a proposal author
The audited Governor path lets an ordinary proposal call the Timelock's privileged setPendingAdmin. The reduction records an attacker-controlled pending administrator wh…
Unbounded external loops can permanently DoS administration — gas-limit denial of service
Loss · Asset approval/liquidation administration becomes uncallable
An ever-growing assetsMapped array is traversed with external approvals. One paused/reverting token traps the whole operation; in production, array growth alone can exce…
Cover Protocol Exploit — Stale `Pool` Snapshot in `Blacksmith.deposit()` Mints ~40 Quintillion COVER
Loss · Effectively unbounded — attacker minted 40,316,176,729,922,452,045 COVER (~4.03e19) again…
Blacksmith is COVER's "shield mining" rewards contract. Each pool tracks an ever-increasing accRewardsPerToken, and each miner stores a rewardWriteoff so that on claim t…
Pickle Finance Exploit — Arbitrary `delegatecall` Through an Approved Jar Converter Drains the DAI pToken Strategy
Loss · ~$19.7M (in the live attack, across multiple pTokens). This PoC reproduces the DAI-jar le…
ControllerV4.swapExactJarForJar() lets a caller pass an array of _targets/_data pairs that the Controller will run with delegatecall inside _execute() (controller-v4.sol…
Harvest Finance Exploit — Vault Share-Price Manipulation via Curve y-Pool Imbalance
Loss · ~$24M total in the live incident (fUSDC + fUSDT pools). This isolated single-tx PoC nets…
Harvest Finance's stablecoin vaults compute the value of one vault share from the current, spot reserves of the Curve y pool (via CRVStrategyStableMainnet.investedUnderl…
bZx (iETH) Exploit — Self-Transfer Balance Duplication in `_internalTransferFrom`
Loss · ~2,388 ETH at the time (the public bZx Sep-2020 incident; this PoC mints 200 ETH of iETH,…
bZx's interest-bearing token (iETH) inherits an ERC20 _internalTransferFrom (LoanTokenLogicWeth.sol:1125-1168) that caches both the sender's and the receiver's balances…
Opyn ETH Put Exploit — Reused `msg.value` Across a Multi-Vault `exercise()` Loop
Loss · ~$371K total drained across the attack campaign; this single reproduced tx nets the attac…
Opyn's oToken is a collateralized options contract. For an ETH-underlying put, exercising an option means: the holder hands the contract the protected underlying (ETH) a…
Balancer × Statera (STA) Exploit — Deflationary-Token Reserve Desync via `gulp()`
Loss · ~455.87 WETH (≈ the pool's entire WETH reserve, ~$104k at the time) drained from the Bala…
Balancer's BPool keeps an internal accounting balance for each bound token in _records[token].balance and prices every swap from that recorded number rather than the poo…
Bancor Network Exploit — Public `safeTransferFrom` Drains Any Approved User
Loss · All ERC20 balances of any user who had an open allowance to the vulnerable Bancor contrac…
Bancor's TokenHandler base contract wraps raw ERC20 calls in a low-level call so that non-standard tokens (no boolean return) don't fail silently. It exposes three helpe…
Lendf.Me Exploit — ERC777 Re-Entrancy on a Checks-Effects-Interactions Violation in `supply()`/`withdraw()`
Loss · ~$25,000,000 — virtually the entire Lendf.Me protocol (all supported assets) drained Apri…
Lendf.Me's MoneyMarket (a fork of Compound v1) records each supplier's balance in supplyBalances[user][asset].principal. Both supply() and withdraw() perform the externa…
Uniswap V1 × imBTC (ERC777) — Reentrancy Reserve-Pricing Drain
UntaggedLoss · +0.0837168576630010 ETH profit from 1 ETH of working capital — the live April-2020 campai…
The Uniswap V1 exchange prices a token→ETH sell by reading the pool's current token balance (self.token.balanceOf(self)) as the input reserve, paying out ETH, and only a…
SpankChain Exploit — Classic Reentrancy in `LedgerChannel.LCOpenTimeout()`
Loss · 155 ETH net profit (160 ETH drained, 5 ETH self-seed returned). Public reports of the liv…
LedgerChannel is a generalized state-channel contract. createChannel() lets a party (Alice) open a channel by depositing ETH and/or an ERC20 token of her own choosing —…
BEC (BeautyChain) Exploit — `batchTransfer()` Integer-Overflow Infinite Mint (`batchOverflow`)
Loss · Token economically destroyed — 2 × 2^255 ≈ 1.16 × 10^59 BEC minted from thin air (each at…
BecToken.batchTransfer() computes the total amount to debit as a plain multiplication:
SmartMesh (SMT) Exploit — `transferProxy` Integer-Overflow Mint (`proxyOverflow` / CVE-2018-10376)
Loss · The bug minted ~5.07 × 10⁵⁸ SMT out of thin air (50,659,039,041,325,835,497,812,305,941,3…
SMT.transferProxy() lets a relayer broadcast a signed transfer on behalf of a token holder and collect a fee. Its very first sanity check is:
Parity WalletLibrary `kill` — Uninitialized Shared Library Self-Destruct (the "devops199" freeze)
Loss · 513,774.16 ETH permanently frozen across ~587 Parity multisig wallets (≈ $150–300M at the…
Parity's multisig wallets were thin proxies: each user's Wallet held only state and forwarded every call via delegatecall into one shared, singleton WalletLibrary deploy…
Parity Multisig First Hack (July 2017) — Unprotected `initWallet` Re-initialization
Loss · 82,189.93 ETH drained from a single victim wallet in the PoC
The Parity multisig wallet was a thin proxy (Wallet) that held the ETH and forwarded every unrecognized call, via delegatecall, to a single shared logic contract (Wallet…
[H-02] Attacker can front-run a MuteBond buyer and lower their payout
Untagged[H-02] Canto asD — permissionless `lzCompose` lets anyone steal a bridged composed-message transfer
Untagged[H-05] Connext routers are not enforced to repay the Aave Portal loan
Untagged[H-46] TOFT `leverageDown` always fails when the TOFT wraps the native gas token
UntaggedAbster Freefall: A player who staked a game in the small-pool token (USDC) claims the payout out of the lar
UntaggedAccountable: A partially-filled redeem controller re-requests; the never-decremented request.totalValue
UntaggedAccountable: A RequestPrice redeemer who locked a 100-asset guarantee at request-time price (1e18) is s
UntaggedAccountable: An async-pending cancel leaves its redeem request queued with shares intact while pendingC
UntaggedAccountable: fulfillCancelRedeemRequest calls _reduce with the pendingRedeemRequest that _fulfillCancel
UntaggedAjna H-05 — cross-pool reward-cap underflow bricks unstake / claimRewards
UntaggedAjna H-06 — a bankrupt bucket wipes a lender's already-earned staking rewards
UntaggedAlchemix: A malicious veALCX holder pokes 3x in one epoch
UntaggedAlchemix: A veALCX holder calls poke() 3x within one epoch (poke lacks the onlyNewEpoch guard that v
UntaggedAmmplify: A compounding maker on a width-8 non-visited node is credited only 1/8 (1 ether) of the 8
UntaggedAmmplify: A user's 100+100 uncollected UniV3 position fees are collected by the decomposer and swept
UntaggedAttacker can stall Forta vault undelegations (locked funds via balance donation)
AZTEC `confidentialApprove` signature replay / revocation inversion
UntaggedThe AZTEC ZkAssetBase.confidentialApprove lets a note owner sign an EIP-712 NoteSignature authorizing (or revoking) a third party to spend a note. In the vulnerable snap…
AZTEC Swap validator: missing elliptic-curve pairing check
UntaggedThe AZTEC Swap validator verifies a confidential swap zero-knowledge proof but omits the elliptic-curve pairing check (validatePairing). The pairing is the only step tha…
Barter DAO: A malicious taker re-enters swap() for a second same-maker order sharing the same takerTok
UntaggedBarter DAO: A one-time signed order authorizing a single 100-makerToken fill is replayed after the mak
UntaggedBMX: An attacker with two addresses in different finalizeEpoch tally batches unstakes 1000e18 s
UntaggedBOB: A user who re-stakes after delegating governance can never withdraw: unbond()/instantWithd
UntaggedBuck Labs: A late inflow disqualifies account A but leaves its 100-token balance in currentEligibleSu
UntaggedBuck Labs: Stale totalExcludedSupply (1
UntaggedBuck Labs: The BandConfig struct mismatch makes LiquidityWindow ABI-decode floorBps from PolicyManage
UntaggedBurve: `ERC4626ViewAdjustor` reverses `toNominal`/`toReal`, inflating LST deposits
UntaggedBurve: `NoopVault` donation attack drains a Closure's assets
UntaggedBurve: Fee bypass in `ValueFacet.removeValueSingle`
UntaggedBurve: incorrect netting zeroes the deposit and over-withdraws
UntaggedColbfinance: Any whitelisted user loops deposit + early-withdraw to inflate the global totalDepositToPr
UntaggedCovenant: With protocol fees on
UntaggedCrestal Network: `Payment::payWithERC20` is public — anyone can drain an approved victim
UntaggedCryptoLegacy: Vesting mixes a live rebasing balance with a stored total, so a rebase makes equal shares pay unequally
UntaggedElytra: A user's elyAsset is burned on requestWithdrawal
UntaggedElytra: getTotalAssetTVL keeps counting the unstaking-vault backing of a pending withdrawal whose
UntaggedElytra: Missing 1e18 scale collapses tempElyAssetPrice to 2 (far below the 18-decimal oldElyAssetP
UntaggedElytra: receiveFromDepositPool reads balanceBefore and balanceAfter with no transfer between them
UntaggedElytra: receiveFromStrategy increments the vault's claimableAssets without decrementing the deposi
UntaggedEpoch Island: withdrawForfeit recomputes the forfeit on an un-scaled reward base, so partial forfeits over-repay
UntaggedEtherspot: A smart-contract wallet's partial invoice payment (40e18 tokens) is permanently locked in
UntaggedEuler HookTargetStakeDelegator double-counts the migrated stake
f(x) Protocol: An attacker uses dust redeems (no minimum rawDebt) to append 800+ child nodes to a tick's
UntaggedFluid DEX v2: `_processNormalSupplyAction` permits an uncapped withdrawal
UntaggedFolks Finance: Missing utilisation-ratio guard: on a fresh pool the attacker pushes totalDebt (1e18) far
UntaggedForte Float128 `Ln.ln` silently accepts non-positive inputs (mispriced settlement / stolen collateral)
GTE: A maker order ground to a sub-minimum one-lot dust rests at the front of the book; a subse
UntaggedGTE: Non-strict crossing check traps min-tick backstop bids
UntaggedGTE: order.prevOrderId written to a memory copy, never persisted
UntaggedH-1: USDC rewards are never distributed if `_updateRewardsStates` is triggered too often
UntaggedHarmonix Finance: Any unprivileged EOA calls the unprotected public testFinalizeSettlement() to flip settlem
UntaggedHarmonix Finance: Anyone front-runs finalizeSettlement() by directly transferring 1 wei of purchaseToken to
UntaggedHinkal: Merkle insert never stores the top root once the tree is half-full, locking every deposit
UntaggedHinkal: Tree capacity guard uses `!=` instead of `<=`, letting an overflow overwrite an earlier commitment
UntaggedHYBUX: A user unstaking through the router forfeits their entire accrued reward (1000 HYBUX): _un
UntaggedHYBUX: Attacker replays a legendary-rarity (weight-100) signature from one NFTStaking deployment
UntaggedHyperlend: After the first successful collateral supply for a token
UntaggedIntentX: claim() reads pending rewards for the zero address, then wipes the caller's real balance unpaid
UntaggedLEND (Lend-V2): cross-chain liquidator seizes collateral without providing repayment
UntaggedLend V2: `_handleBorrowCrossChainRequest` distributes LEND on an already-inflated balance
UntaggedLend V2: a liquidated CoreRouter overpays early redeemers and strands the last
UntaggedLend V2: cross-chain collateral is miscounted as zero in `borrowWithInterest`
UntaggedLend V2: cross-chain liquidation check misuses `payload.amount`
UntaggedLEND V2: cross-chain liquidation computes `maxLiquidatable` incorrectly
UntaggedLend V2: cross-chain liquidation reduces debt by the collateral seized
UntaggedLend V2: incorrect LEND reward distribution for cross-chain borrows
UntaggedLend V2: wrong lToken seize amount in cross-chain liquidation
UntaggedLend: `borrowWithInterest` scales cross-chain debt by the same-chain borrow index
UntaggedLEND: `claimLend` never resets accrued rewards, draining LEND reserves
UntaggedLend: `CoreRouter.borrow()` uses an incorrect collateral check
UntaggedLEND: `CoreRouter.redeem` overpays a precomputed amount, draining its reserve
UntaggedLEND: `CoreRouter.supply` credits lTokens with a stale exchange rate
Lend: borrower can redeem collateral immediately after a cross-chain borrow
UntaggedLEND: Cross-chain borrow ignores existing debt in collateral validation
UntaggedLEND: cross-chain liquidation uses the wrong `srcToken`
UntaggedLend: cross-chain repayment updates the wrong borrow balance
UntaggedLEND: cross-chain repayment wipes the borrower's same-chain debt
UntaggedLend: liquidation `protocolReward` is permanently stuck
UntaggedLoopFi PrelaunchPoints — H-01: availability-of-deposit invariant can be bypassed
UntaggedMajority Protocol: An attacker's referrer claims 10 MJT of unbacked referral rewards (5 sock-puppets join+lea
UntaggedMajority Protocol: In a game with no referrers
UntaggedMalda: A semi-trusted rebalancer forwards the operator-supplied
UntaggedManifestFinance: A FULL_RESTRICTED (blacklisted/sanctioned) caller successfully deposits and mints 1000e18
UntaggedManifestFinance: The first depositor into a fresh (totalSupply==0) sUSH vault receives 0 shares for a posit
UntaggedMultipli: Reported yield instantly reprices shares, so a same-block sandwich siphons the LP's yield
UntaggedMyriad: An oracle-voided market (outcome -1) resolves without setting voidedPayouts
UntaggedNLX Oracle: multiple in-block price fetches enable risk-free arbitrage
UntaggedNotional Finance: Curve-gauge LP stakers receive 0 accrued CRV on exit because _unstakeLpTokens calls withdr
UntaggedNUTS Finance: A valid large feed price (>~$100k) overflows getPrice()'s plain 256-bit `compositePrice *
UntaggedNUTS Finance: Because rebase()'s oldD>newD branch never syncs balances/totalSupply
UntaggedOlas H-02 — Arbitrary tokens and data can be bridged to `GnosisTargetDispenserL2`
UntaggedOpenLeverage `LPool.doTransferOut` — native `transfer` 2300-gas stipend freezes contract lenders' funds
UntaggedOrigin Dollar (OUSD): `CompoundStrategy.liquidate()` ignores Compound's redeem error code
UntaggedOstium: A 3 USDC liquidation fee routed via OstiumVault.receiveAssets enters the vault's USDC bala
UntaggedParaSpace: uint8 asset index truncates past 255 assets, colliding slots
UntaggedPear: Any caller redeems a victim's ERC4626 vault shares to themselves — victim's 1000e18 shares
UntaggedPino C-01 — `Curve::withdraw` strands users' native ETH
UntaggedRadius Technology: Expired auth tokens are pruned from the custom group ledger but never burned from the auth
UntaggedRegnumAurum: A dust borrow resets position.positionIndex to the current usageIndex while adding only pr
UntaggedRemora: A single canTransfer from InvestorA inflates the allowance of EntityB and EntityD (entitie
UntaggedRemora: resolveUser migrates a departing investor's pending dividend into DividendManager._resolve
UntaggedRenzo bridge: xezETH supply desyncs from ezETH backing (H-06)
UntaggedSource: Code4rena 2024-04-renzo, commit b5b5b76aeafd26c3607d1f0cda6835934d9e7b9e (https://github.com/code-423n4/2024-04-renzo). Vulnerable files: contracts/Bridge/L2/xRe…