ApeCoin Hack

Reported loss $820K
Ethereum
Flashloan Governance Attack

What happened

On March 17, 2022, minutes after the ApeCoin (APE) airdrop to Bored Ape Yacht Club (BAYC) and Mutant Ape holders opened, an attacker used an NFT flash loan from the NFTX BAYC vault to claim 60,564 APE in a single transaction. The airdrop contract paid out to whoever held an eligible ape at the moment of claiming, not to holders recorded in an earlier snapshot, so apes borrowed for one transaction were enough.

The attacker sold most of the APE for about 293 ETH, reported at roughly $820,000. Amber Group's reproduction, which subtracts the 106 ETH spent on BAYC #1060 and the ETH recovered afterwards, puts the net profit nearer $350,000.

How it happened

  1. The attacker bought BAYC #1060 on OpenSea for 106 ETH and moved it into their exploit contract, to cover NFTX redemption and minting fees.
  2. The contract flash-borrowed BAYC vTokens from the NFTX BAYC vault and redeemed them for the five apes the vault held (IDs 7594, 8214, 9915, 8167 and 4755).
  3. Holding those apes, it called claimTokens() on the AirdropGrapesToken contract and received 60,564 APE.
  4. It deposited the apes back into NFTX (plus #1060) to mint vTokens, repaid the flash loan, and swapped the leftover vTokens for about 14 ETH on SushiSwap.
  5. The attacker then sold most of the APE for about 293 ETH.

Exploit transaction: 0xb4fa6d557d55183a8c583fa7d24b9f4916c1322a5253383d4f335255a2cfd729.

Protocol details

Classification Governance
Protocol Type Yield
Protocol links Website @apecoin

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.