ApeCoin Hack
What happened
On March 17, 2022, minutes after the ApeCoin (APE) airdrop to Bored Ape Yacht Club (BAYC) and Mutant Ape holders opened, an attacker used an NFT flash loan from the NFTX BAYC vault to claim 60,564 APE in a single transaction. The airdrop contract paid out to whoever held an eligible ape at the moment of claiming, not to holders recorded in an earlier snapshot, so apes borrowed for one transaction were enough.
The attacker sold most of the APE for about 293 ETH, reported at roughly $820,000. Amber Group's reproduction, which subtracts the 106 ETH spent on BAYC #1060 and the ETH recovered afterwards, puts the net profit nearer $350,000.
How it happened
- The attacker bought BAYC #1060 on OpenSea for 106 ETH and moved it into their exploit contract, to cover NFTX redemption and minting fees.
- The contract flash-borrowed BAYC vTokens from the NFTX BAYC vault and redeemed them for the five apes the vault held (IDs 7594, 8214, 9915, 8167 and 4755).
- Holding those apes, it called
claimTokens()on theAirdropGrapesTokencontract and received 60,564 APE. - It deposited the apes back into NFTX (plus #1060) to mint vTokens, repaid the flash loan, and swapped the leftover vTokens for about 14 ETH on SushiSwap.
- The attacker then sold most of the APE for about 293 ETH.
Exploit transaction: 0xb4fa6d557d55183a8c583fa7d24b9f4916c1322a5253383d4f335255a2cfd729.
Protocol details
Evidence
- analysis DeFiLlama defillama.com
- analysis Reproducing the $APE Airdrop Flash Loan Arbitrage/Exploit (Amber Group / Chiachih Wu, 2022-03-22) amberlabs.substack.com
- analysis How Someone Made $820K From ApeCoin's Airdrop Via Flashloan (CryptoPotato, 2022-03-17) cryptopotato.com
- analysis apecoin.com page apecoin.com apecoin.com
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.