Affine Protocol Hack
What happened
Affine Protocol's Boosted ETH Staking basket on Ethereum lost about 33 aEthwstETH (about $88,000) on February 1, 2024. Its LidoLevV3 strategy contract implemented Balancer's receiveFlashLoan callback. The callback checked only that the caller was the Balancer vault, then decoded an action type and a newStrategy address from userData and acted on them.
Balancer lets anyone take a flash loan and name any contract as the recipient, so the attacker could make the strategy run its privileged close-out and migration branches with inputs the attacker chose. The attacker was funded through Tornado Cash. Affine paused its vaults, sent the attacker an on-chain message asking for the funds back, deprecated the affected basket contracts, urged users to revoke approvals, and published a post-mortem with refund options for affected users.
How it happened
- The attacker called Balancer's
flashLoanwithLidoLevV3as the recipient, borrowing about 319 WETH, withuserDataset toLoanType.divest. Balancer calledreceiveFlashLoan, which ran_endPositionand unwound the strategy's Aave position. - The attacker called
flashLoanagain for 0 WETH, still withLidoLevV3as recipient, this time withuserDataset toLoanType.upgradeandnewStrategypointing to the attacker's own contract. - The
upgradebranch ran_payDebtAndTransferCollateral, which repaid the strategy's Aave debt and sent all of its aToken collateral (about 33 aEthwstETH) tonewStrategy. - The branch then called
newStrategy.createAaveDebt(debt). The attacker's contract implemented it as a no-op, so it kept the collateral without taking on any debt.
Protocol details
Evidence
- report Phalcon alert on AffineDeFi x.com
- report Cyvers alert on AffineDeFi x.com
- analysis DeFiLlama defillama.com
- analysis How Was Affine Protocol Exploited? (Neptune Mutual, Wayback copy) neptunemutual.com
- analysis Lack of Validation in Input Data - The Case of AffineDeFi (Verichains) blog.verichains.io
- analysis DeFiHackLabs AffineDeFi_exp.sol raw.githubusercontent.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.