Acala Hack

Reported loss Not disclosed
Acala
Infinite Mint

What happened

On August 14, 2022, a misconfigured reward setting on Acala, a DeFi parachain on Polkadot, let liquidity providers receive billions of unbacked aUSD, Acala's stablecoin. The new iBTC/aUSD pool on Acala Swap had just gone live. Its rewards were meant to be paid in ACA and INTR, but they were set to pay aUSD, and the code did not stop that parameter error. When liquidity providers claimed their rewards, the protocol minted aUSD with no collateral behind it.

First reports counted about 1.28 to 1.3 billion aUSD. Acala's full trace report later counted 3.022 billion aUSD claimed by 16 addresses. aUSD fell as low as about $0.01. An emergency governance vote paused Acala Swap and the Honzon stablecoin protocol while the team traced the funds. The largest single recipient received about 1.27 billion aUSD.

Acala recovered about 2.97 billion aUSD. About 1.29 billion was burned after a governance vote on August 15, and another 1.68 billion held as iBTC/aUSD LP tokens after a vote around August 20. Some recipients had already swapped their aUSD for other tokens and moved them to other chains. About 48 million aUSD was not recovered.

Address breakdown: https://hackmd.io/@xlc/SkN2HdDA9

How it happened

  1. Acala launched the iBTC/aUSD liquidity pool on Acala Swap, with liquidity rewards configured in aUSD instead of ACA and INTR.
  2. Liquidity providers in the pool claimed their rewards. Each claim minted new aUSD without collateral.
  3. Sixteen addresses claimed a total of 3.022 billion aUSD. Some swapped part of it for other tokens and sent it to other chains, and aUSD lost its peg.
  4. Governance paused Acala Swap and Honzon, traced the error mints and voted to burn about 2.97 billion recovered aUSD. About 48 million aUSD stayed out of reach.

Protocol details

Classification Token & Share Accounting
Protocol Type Canonical Bridge
Affected asset / contract aUSD
Implementation language Rust
Protocol links Website @AcalaNetwork

Security review history

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.