Alkimiya Hack

Reported loss $96K
Ethereum
Arithmetic Error

What happened

Alkimiya's SilicaPools contract on Ethereum was exploited on March 28, 2025 for 1.14 WBTC, about $95,500. collateralizedMint accepted a 256-bit share amount but stored it as a 128-bit number. Minting 2^128 + 1 shares therefore recorded only 1 share minted, and a later redemption paid out roughly twice the WBTC collateral that had been deposited.

The MEV bot Yoink front-ran the original attacker (0xF6ffBa5cbF285824000daC0B9431032169672B6e), whose own transaction reverted. In a statement, Alkimiya said it took the affected parts of its system offline, that a known whitehat had front-run the attack, that all funds had been returned, and it thanked SEAL for help.

How it happened

  1. The attacker flash-borrowed 10 WBTC from Morpho.
  2. It called SilicaPools.collateralizedMint() asking for 2^128 + 1 shares while depositing about 1.7 WBTC as collateral. The full share amount was minted, but the unsafe uint128 cast recorded sharesMinted as 1.
  3. It transferred 2^128 - 1 shares to another address, keeping 2 shares, then started and ended the pool.
  4. It called redeemShort(). Because the pool believed only 1 share existed and the attacker held 2, it paid out about 3.4 WBTC, twice the deposit.
  5. The attacker repaid the flash loan and kept 1.14 WBTC, which it swapped for about 50.9 ETH on Uniswap V3.

Protocol details

Classification Token & Share Accounting
Protocol Type Derivatives
Implementation language Solidity
Protocol links @alkimiya_io

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.