ALP Hack
What happened
On March 6, 2024 a portfolio vault on BNB Chain that held an ApolloX ALP position was drained of about $10.6K. The vault's swap helper _swap(tokenForSwap, aggregatorData) was meant to be internal plumbing for routing deposits and redemptions through the 1inch router, but it was deployed as a public function with no access control. Anyone could make the vault approve 1inch for its entire balance of any token and then forward attacker-written calldata to the router.
The attacker used this to move the vault's whole ALP vault-share balance (about 8.69e21 units) to their own contract, then redeemed those shares through the normal ApolloX redeem path for about 10,611 USDT. The vault's depositors were left holding shares with no ALP behind them.
Attack tx: 0x9983ca8eaee9ee69629f74537eaf031272af75f1e5a7725911d8b06df17c67ca
Attacker: 0xff61Ba33Ed51322BB716EAb4137Adf985644b94d
How it happened
- The attacker read the vault's balance of the ALP vault-share token (
0x9Ad45D46...0e0d), about 8.69e21 units. - They called the vault's public
_swapwith that token and calldata for 1inchunoswapTo, naming their own contract as recipient, the full balance as amount,minReturnof 0, and a pool descriptor that pointed at their own contract. _swapapproved the 1inch router for the vault's full token balance and executed the calldata, so the router pulled every share out of the vault and delivered it to the attacker.- The attacker called
redeemon the share token, which unstaked and burned the underlying ALP at ApolloX and paid out about 10,611 USDT.
Protocol details
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.