Abracadabra Money Hack
What happened
On January 30, 2024, an attacker exploited a rounding flaw in older Abracadabra Cauldron V4 contracts on Ethereum. The debt-accounting error let the attacker make a large MIM borrow appear adequately collateralized, extracting about $6.5 million in MIM.
Precision loss in Cauldron V4 token/share debt accounting. Repayment and rebase conversions allowed total debt and debt-share accounting to diverge, so the solvency calculation could value a large borrow part as effectively negligible and accept an inadequately collateralized borrow.
Case & protocol details
Attack Timeline
The attacker used temporary MIM liquidity to manipulate repayment and debt-share accounting in the affected Cauldrons. Repayments drove the aggregate debt rebase into an abnormal state where debt shares remained but their calculated value became negligible. The attacker could then borrow unbacked MIM while the solvency calculation passed, repay the temporary liquidity, and move the proceeds.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report twitter.com
- report Post-mortem rekt.news
- transaction Transaction etherscan.io
- analysis Web Archive archive.ph
- analysis Abracadabra DAO: Resilience Rising paragraph.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.