Abracadabra Spell Hack

TOTAL LOST $13.0M
High Other arbitrum

What happened

On March 25, 2025, Abracadabra.Money was exploited for $13 million (6,260 ETH) due to state tracking errors in GMX-linked cauldrons, allowing the attacker to self-liquidate positions and take bad loans without repaying them. The stolen funds were bridged from Arbitrum to Ethereum and laundered via Tornado Cash.

The attack abused GMX-based cauldrons, which track collateral states for loans. The attacker failed a GMX deposit, leaving funds stuck in the OrderAgent contract, then self-liquidated a borrowed position, causing the system to erase it without removing collateral. This allowed them to borrow again using already liquidated collateral, effectively draining $13 million from the protocol.

The funds were bridged from Arbitrum to Ethereum and washed through Tornado Cash. Despite initial confusion, GMX contracts were not directly affected, and Abracadabra has offered a 20% bounty for fund recovery.

Exploit tx:

https://arbiscan.io/tx/0xed17089a…5ef0b0

Exploiter:

https://arbiscan.io/address/0xaf9e33aa…c38649

Case & protocol details

Classification Protocol Logic / Exchange (DEX),Yield Aggregator
Protocol Type CDP
Smart Contract Language Solidity
Official Website abracadabra.money/
Protocol Twitter/X @MIM_Spell

Evidence & learning

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.