AROS Hack
What happened
On 30 May 2026 an attacker drained about 295,314 USDT from the AROS/USDT PancakeSwap pool on BNB Chain. AROS is an upgradeable token that pays out claims (principal, yield, lucky and contribution rewards) when the user presents an EIP-712 signature from a claimSigner key. The attacker used two valid claim signatures made out to their own address. crypto.training's analysis says the signer key was leaked; DeFiHackLabs labels the bug signature replay.
The design made this worse: claims were paid by moving AROS straight out of the live liquidity pool, not from a treasury wallet. Nested flash loans and borrows let the attacker buy up almost all the AROS in the pool, use the claims to strip what remained, and then sell back into a pool with almost no AROS left. TenArmor flagged the attack on 1 June 2026. No project post-mortem or fund recovery has been reported.
How it happened
- The attacker raised about 206.4M USDT through nested flash loans and borrows: a Lista Moolah flash loan, Venus and Aave borrows, a Balancer V3 take, and flashes from 25 PancakeSwap and Uniswap V3 pools.
- They swapped it for about 621.9M AROS, roughly 99.85% of the pool's AROS, leaving about 910K AROS in the pair.
- They called
claimPrincipalwith a validclaimSignersignature bound to their address. The claim helper_drainFromLPTotransferred about 199K AROS directly out of the pair. - A second signed
claimYieldcall took about 710.8K more AROS out of the pair across three recipients (the attacker, a referral pool and a dividend pool), leaving the pair's AROS reserve close to zero without a matching USDT outflow. - The attacker sold the AROS they held into the now AROS-starved pool, took back the borrowed USDT plus about 301K USDT of real liquidity, repaid the flash loans, and kept about 295,314 USDT (tx
0xe89fe640ec5241edfca7d8dcae77a0a4270dee15e4bbd043fc60e393aabf41e1).
Protocol details
Evidence
- analysis DeFiLlama defillama.com
- analysis AROS exploit - crypto.training reproduced on-chain exploits crypto.training
- analysis DeFiHackLabs AROS_exp.sol PoC raw.githubusercontent.com
- analysis DeFiHackLabs README entry: 20260530 AROS - Signature Replay raw.githubusercontent.com
- analysis TenArmor: A suspicious attack involving AROS detected on BSC bitget.com
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.