Open in app

Sign In

Write

Sign In

WatchPug
WatchPug

284 Followers

Home

About

Oct 20, 2021

PancakeHunny Flash Loan Minting Attack Analysis

The Exploit On Oct 20, 9 AM UTC, an attacker exploited PancakeHunny by manipulating the price of WBNB/TUSD on PCS using flash loans, minted ~12M of Hunny tokens in 15 transactions, and dumped. As a result, the hacker has taken out 2.3M (642k of stable coin + 435.31 ETH) and crashed the…

Flash Loan

2 min read

PancakeHunny Flash Loan Minting Attack Analysis
PancakeHunny Flash Loan Minting Attack Analysis
Flash Loan

2 min read


Aug 4, 2021

Wault WUSD Minting Attack Root Cause Analysis

An economic attack rooted in the design of WUSD — WUSD is a stable coin backed by USDT and WEX. When you mint WUSD with USDT, 1/10 of the deposit will be used for market buy WEX and then use the WEX bought as part of the reserve. The Exploit At around 2 AM UTC on Aug 4, Wault’s WUSD on BSC…

Bsc

2 min read

Wault WUSD Minting Attack Root Cause Analysis
Wault WUSD Minting Attack Root Cause Analysis
Bsc

2 min read


Jul 14, 2021

ApeRocket (Polygon) Performance Fee Minting Incident Root Cause Analysis

The Exploit At around 8 AM UTC on July 14, ApeRocket’s MATIC-DAI vault on Polygon was exploited and drained $1M (521 ETH) out of the SPACE token LP on Polygon. Check out the Transaction Details on PolygonScan. How? Borrowed 24M DAI and 54M MATIC of flash loans from Aave. Created 25M DAIMATIC LP. …

2 min read

ApeRocket (Polygon) Performance Fee Minting Incident Root Cause Analysis
ApeRocket (Polygon) Performance Fee Minting Incident Root Cause Analysis

2 min read


Jul 14, 2021

ApeRocket (BSC) Performance Fee Minting Incident Root Cause Analysis

The Exploit At around 4:30 AM UTC on July 14, ApeRocket’s CAKE vault was exploited and drained $260K (883 BNB) out of the SPACE token LP on ApeSwap. Check out the Transaction Details on BscScan. How? Borrowed 1.6M CAKE ($21.8M) of flash loan from PancakeSwap. Added 509K CAKE of deposit to the CAKE…

Bsc

2 min read

ApeRocket (BSC) Performance Fee Minting Incident Root Cause Analysis
ApeRocket (BSC) Performance Fee Minting Incident Root Cause Analysis
Bsc

2 min read


Jun 28, 2021

SafeDollar exploit root cause analysis

Those who cannot learn from history are doomed to repeat it. — The Exploit At around 3:48 AM UTC on Jun 28, a hacker managed to mint a huge amount of SDO (an algo stablecoin on Polygon) and dumped them into the market. How many? 831,309,277,244,108,000 SDO That’s a lot. As a result, the hacker has taken out 202k USDC and 46k USDT. …

Polygon

2 min read

SafeDollar exploit root cause analysis
SafeDollar exploit root cause analysis
Polygon

2 min read


Jun 21, 2021

Impossible Finance exploit root cause analysis

How does Impossible Finance make the impossible possible? — The Exploit At around 4:40 AM UTC on Jun 21, $0.5M (229.84 ETH) was stolen from Impossible Finance. Using a vulnerability in the LP contract, the hacker managed to swap IF into BUSD at about the price 2 times in a row, which is usually “Impossible” because of the slippage. As a…

Bsc

2 min read

Impossible Finance exploit root cause analysis
Impossible Finance exploit root cause analysis
Bsc

2 min read


Jun 3, 2021

PancakeHunny Performance Fee Minting Attack Analysis

The Exploit On Jun 03, about 2 AM UTC, with a lot of Hunny tokens minted out and dumped, the hacker has taken out 38.9 ETH.

2 min read

PancakeHunny Performance Fee Minting Attack Analysis
PancakeHunny Performance Fee Minting Attack Analysis

2 min read


May 26, 2021

Merlin Lab Performance Fee Minting Incident Analysis

Fool me once, shame on you. Fool me twice, shame on me. Fool me three times, shame on both of us. — Disclosures: Merlin Lab has engaged WatchPug to perform the 4th audit on their updated security code. The Exploit On May 26, 2021, 03:59:05 AM +UTC, less than 48 hrs after the Autoshark hack. Merlin Lab, well, another Bunny fork, been attacked in a similar fashion to the Bunny and the Autoshark hack.

Bsc

2 min read

Merlin Lab Performance Fee Minting Incident Analysis
Merlin Lab Performance Fee Minting Incident Analysis
Bsc

2 min read


May 25, 2021

Autoshark Performance Fee Minting Incident Analysis

A copycat hack targeted at a copycat platform — The Exploit On May 24, 2021, 09:41:49 PM +UTC, less than 5 days after the bunny hack. A copycat hacker used 100K BNB of flash loan and minted 135M of SHARK token from Autoshark, a copycat of Bunny. As a result, the hacker has taken out 2.2k WBNB. Check out the Transaction…

2 min read

Autoshark Performance Fee Minting Incident Analysis
Autoshark Performance Fee Minting Incident Analysis

2 min read


May 20, 2021

The PancakeBunny Bunny Performance Fee Minting Incident Analysis

The root cause: lack of understanding of the dependent smart contracts. The Exploit On May 19, 2021, 10:34:28 PM +UTC, with two transactions, the hacker used 2.3M BNB and 2.9M USDT of flash loan and minted 6,972,455 BUNNY token. As a result of this exploit, the hacker has taken out 114k WBNB…

4 min read

The PancakeBunny Bunny Performance Fee Minting Incident Analysis
The PancakeBunny Bunny Performance Fee Minting Incident Analysis

4 min read

WatchPug

WatchPug

284 Followers

Pug against Rug

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech