Abracadabra Spell Hack
What happened
On March 25, 2025, Abracadabra.Money was exploited for $13 million (6,260 ETH) due to state tracking errors in GMX-linked cauldrons, allowing the attacker to self-liquidate positions and take bad loans without repaying them. The stolen funds were bridged from Arbitrum to Ethereum and laundered via Tornado Cash.
The attack abused GMX-based cauldrons, which track collateral states for loans. The attacker failed a GMX deposit, leaving funds stuck in the OrderAgent contract, then self-liquidated a borrowed position, causing the system to erase it without removing collateral. This allowed them to borrow again using already liquidated collateral, effectively draining $13 million from the protocol.
The funds were bridged from Arbitrum to Ethereum and washed through Tornado Cash. Despite initial confusion, GMX contracts were not directly affected, and Abracadabra has offered a 20% bounty for fund recovery.
Exploit tx:
https://arbiscan.io/tx/0xed17089a…5ef0b0
Exploiter:
https://arbiscan.io/address/0xaf9e33aa…c38649
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report x.com
- analysis Website reference x.com
- analysis Website reference binance.com
- analysis Website reference halborn.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.