88mph Hack

Reported loss Not disclosed
Ethereum
Missing Input Validation

What happened

88mph is a protocol for earning fixed-rate interest on crypto. On June 7, 2021, whitehat Ashiq Amien of iosiro reported a critical bug to Immunefi in three 88mph pools: yaLINK, Harvest CRV:STETH and Harvest CRV:RENWBTC. The init() function of each pool's deposit NFT contract was unprotected. Anyone could call it and become the contract's owner, and the owner could mint and burn deposit NFTs. About $6.5 million, mostly crvRenWBTC, was at risk.

The contracts were not pausable or upgradeable, so on Immunefi's suggestion 88mph set the NFT minter to a dummy contract that reverted on every call. That stopped anyone from front-running the rescue. On June 8, 2021, at 21:46 UTC, 88mph whitehacked the funds to its multisig and then returned them to users. No user funds were lost. 88mph paid iosiro a $42,069 bounty.

How it happened

  1. The deposit NFT contracts had an init() function with no onlyOwner modifier and no one-time initializer guard, so anyone could call it at any time.
  2. Calling init() handed contract ownership to the caller.
  3. As owner, the caller could burn any user's deposit NFT and mint new ones to themselves, taking control of the deposits behind them. DeFiHackLabs' reproduction does exactly this on the yaLINK deposit NFT.
  4. No attacker used the bug. 88mph first blocked minting by setting the minter to a dummy contract that reverted on every call, then moved the at-risk funds to its multisig in a whitehack and returned them to users.

Protocol details

Classification Input Validation
Protocol Type Lending
Implementation language Solidity
Protocol links Website @88mphapp

Security review history

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.