APEMAGA Hack

Reported loss $32K
Ethereum
Unknown

What happened

On June 27, 2024, the APEMAGA token on Ethereum lost about 9.37 ETH (roughly $32,000) from its Uniswap V2 pool. The token had a public family(address) function with no caller check, and it burned almost the entire balance of whatever address was passed in. The attacker pointed it at the liquidity pair, burned nearly all of the pool's APEMAGA, synced the reserves, and sold a small APEMAGA holding into the pool at a hugely inflated price. ChainAegis reported 59,632,616 APEMAGA converted to 9.37 ETH.

Attacker: 0xb297735e9fb3e695ccce3963bfe042f318901ea0.

How it happened

  1. The attacker bought a small amount of APEMAGA with ETH on Uniswap V2 to hold for the later sale.
  2. It called family(address(pair)) three times. Each call ran the internal _approve_ routine on the pair's balance and burned about 99.9% of it, leaving the pair with almost no APEMAGA.
  3. It called sync() on the pair so the recorded APEMAGA reserve dropped to near zero while the WETH reserve stayed the same.
  4. It swapped its APEMAGA for WETH. Because the pool now priced APEMAGA as extremely scarce, the swap paid out most of the pool's WETH.

Protocol details

Classification Protocol Logic
Protocol Type DeFi Protocol
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.