Abracadabra Spell Hack

TOTAL LOST $6.5M
Medium Arithmetic Overflow & Underflow Attacks Ethereum

What happened

Abracadabra Money lost about $6.5 million on Ethereum after a debt-accounting precision-loss flaw in legacy Cauldron V4 enabled unbacked MIM borrowing and a liquidity drain. The DAO recapitalized the shortfall from treasury; this was not an attacker-fund recovery.

Technical Root Cause

Cauldron V4's debt accounting tracked an amount and debt parts that could be driven out of sync through precision loss. The solvency calculation relied on their ratio, allowing crafted borrow and repay operations to bypass the intended collateral constraint.

Case & protocol details

Classification Borrowing and lending / debt-accounting precision loss
Protocol Type CDP
Smart Contract Language Solidity
Official Website abracadabra.money/
Protocol Twitter/X @MIM_Spell

Attack Timeline

The attacker flash-loaned MIM from DegenBox, donated and deposited it into BentoBox, then used repayForAll to create a mismatch between global debt amount and debt parts. Repeated borrow and repay operations made borrow parts disproportionately large, defeating the solvency calculation and enabling unbacked MIM borrowing.

The DAO set borrow limits to zero for affected cauldrons, stated collateral was not at risk, and used treasury reserves to fully collateralize the shortfall. There is no verified evidence that the attacker returned funds.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.