Abracadabra Money Hack

TOTAL LOST $6.4M
Medium Arithmetic Overflow & Underflow Attacks ethereum

What happened

On January 30, 2024, an attacker exploited a rounding flaw in older Abracadabra Cauldron V4 contracts on Ethereum. The debt-accounting error let the attacker make a large MIM borrow appear adequately collateralized, extracting about $6.5 million in MIM.

Technical Root Cause

Precision loss in Cauldron V4 token/share debt accounting. Repayment and rebase conversions allowed total debt and debt-share accounting to diverge, so the solvency calculation could value a large borrow part as effectively negligible and accept an inadequately collateralized borrow.

Case & protocol details

Classification Token & Share Accounting
Protocol Type Exploit/Other
Affected asset / contract MIM
Official Website abracadabra.money/
Protocol Twitter/X @MIM_Spell

Attack Timeline

The attacker used temporary MIM liquidity to manipulate repayment and debt-share accounting in the affected Cauldrons. Repayments drove the aggregate debt rebase into an abnormal state where debt shares remained but their calculated value became negligible. The attacker could then borrow unbacked MIM while the solvency calculation passed, repay the temporary liquidity, and move the proceeds.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.