Alkimiya Hack
What happened
Alkimiya's SilicaPools contract on Ethereum was exploited on March 28, 2025 for 1.14 WBTC, about $95,500. collateralizedMint accepted a 256-bit share amount but stored it as a 128-bit number. Minting 2^128 + 1 shares therefore recorded only 1 share minted, and a later redemption paid out roughly twice the WBTC collateral that had been deposited.
The MEV bot Yoink front-ran the original attacker (0xF6ffBa5cbF285824000daC0B9431032169672B6e), whose own transaction reverted. In a statement, Alkimiya said it took the affected parts of its system offline, that a known whitehat had front-run the attack, that all funds had been returned, and it thanked SEAL for help.
How it happened
- The attacker flash-borrowed 10 WBTC from Morpho.
- It called
SilicaPools.collateralizedMint()asking for 2^128 + 1 shares while depositing about 1.7 WBTC as collateral. The full share amount was minted, but the unsafeuint128cast recordedsharesMintedas 1. - It transferred 2^128 - 1 shares to another address, keeping 2 shares, then started and ended the pool.
- It called
redeemShort(). Because the pool believed only 1 share existed and the attacker held 2, it paid out about 3.4 WBTC, twice the deposit. - The attacker repaid the flash loan and kept 1.14 WBTC, which it swapped for about 50.9 ETH on Uniswap V3.
Protocol details
Evidence
- report TenArmor Security Alert on Alkimiya x.com
- report Alkimiya statement on the attack (Leozayaat on X) x.com
- transaction Etherscan attack transaction 0x9b9a6dd0...0814 etherscan.io
- analysis DeFiLlama defillama.com
- analysis Alkimiya Hack Analysis (Verichains) blog.verichains.io
- analysis DeFiHackLabs Alkimiya_io_exp.sol raw.githubusercontent.com
- analysis Alkimiya SilicaPools uint128 Truncation Unsafe Downcasting (Quadriga Initiative) quadrigainitiative.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.