ALP Hack

Reported loss $10K
BNB Chain
Improper Access Control

What happened

On March 6, 2024 a portfolio vault on BNB Chain that held an ApolloX ALP position was drained of about $10.6K. The vault's swap helper _swap(tokenForSwap, aggregatorData) was meant to be internal plumbing for routing deposits and redemptions through the 1inch router, but it was deployed as a public function with no access control. Anyone could make the vault approve 1inch for its entire balance of any token and then forward attacker-written calldata to the router.

The attacker used this to move the vault's whole ALP vault-share balance (about 8.69e21 units) to their own contract, then redeemed those shares through the normal ApolloX redeem path for about 10,611 USDT. The vault's depositors were left holding shares with no ALP behind them.

Attack tx: 0x9983ca8eaee9ee69629f74537eaf031272af75f1e5a7725911d8b06df17c67ca Attacker: 0xff61Ba33Ed51322BB716EAb4137Adf985644b94d

How it happened

  1. The attacker read the vault's balance of the ALP vault-share token (0x9Ad45D46...0e0d), about 8.69e21 units.
  2. They called the vault's public _swap with that token and calldata for 1inch unoswapTo, naming their own contract as recipient, the full balance as amount, minReturn of 0, and a pool descriptor that pointed at their own contract.
  3. _swap approved the 1inch router for the vault's full token balance and executed the calldata, so the router pulled every share out of the vault and delivered it to the attacker.
  4. The attacker called redeem on the share token, which unstaked and burned the underlying ALP at ApolloX and paid out about 10,611 USDT.

Protocol details

Classification Access Control
Protocol Type DeFi Protocol
Implementation language Solidity

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.