Affine Protocol Hack

Reported loss $88K
Ethereum
Missing Input Validation

What happened

Affine Protocol's Boosted ETH Staking basket on Ethereum lost about 33 aEthwstETH (about $88,000) on February 1, 2024. Its LidoLevV3 strategy contract implemented Balancer's receiveFlashLoan callback. The callback checked only that the caller was the Balancer vault, then decoded an action type and a newStrategy address from userData and acted on them.

Balancer lets anyone take a flash loan and name any contract as the recipient, so the attacker could make the strategy run its privileged close-out and migration branches with inputs the attacker chose. The attacker was funded through Tornado Cash. Affine paused its vaults, sent the attacker an on-chain message asking for the funds back, deprecated the affected basket contracts, urged users to revoke approvals, and published a post-mortem with refund options for affected users.

How it happened

  1. The attacker called Balancer's flashLoan with LidoLevV3 as the recipient, borrowing about 319 WETH, with userData set to LoanType.divest. Balancer called receiveFlashLoan, which ran _endPosition and unwound the strategy's Aave position.
  2. The attacker called flashLoan again for 0 WETH, still with LidoLevV3 as recipient, this time with userData set to LoanType.upgrade and newStrategy pointing to the attacker's own contract.
  3. The upgrade branch ran _payDebtAndTransferCollateral, which repaid the strategy's Aave debt and sent all of its aToken collateral (about 33 aEthwstETH) to newStrategy.
  4. The branch then called newStrategy.createAaveDebt(debt). The attacker's contract implemented it as a no-op, so it kept the collateral without taking on any debt.

Protocol details

Classification Input Validation
Protocol Type DeFi Protocol
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.