Auctus Hack
What happened
On March 26, 2022, attackers stole about $726,000 in tokens, including USDC, from users of Auctus, a decentralized options protocol on Ethereum. The flaw was in an old beta contract, ACOWriter (0xE7597F774fD0a15A617894dc39d45A28B97AFa4f), which let users mint options and sell them on an exchange in one step. To use it, they had to approve it to spend their tokens. The contract let the caller choose which "exchange" to call and what data to send without checking either, so anyone could make it spend those approvals.
Auctus warned users on March 29, 2022, three days after the main theft, and asked everyone who had ever approved the contract to revoke that approval. Smaller copycat drains followed, and Revoke.cash puts the total at more than $750,000. The contract is still on-chain, so any approval to it that was never revoked is still at risk.
How it happened
- Users who wrote options through
ACOWriterhad given it ERC-20 approvals, often unlimited, for tokens such as USDC. ACOWriter.write()takes an exchange address and raw exchange calldata, and forwards the call without checking either one.- The attacker called
write()with a fake option token contract they controlled, set the USDC token contract as the "exchange", and passed calldata fortransferFrom(victim, attacker, amount). ACOWritermade that call itself. Because it held the victim's approval, USDC moved from the victim's wallet to the attacker.- The attacker repeated this against approving wallets. Exploit transaction:
0x2e7d7e7a6eb157b98974c8687fbd848d0158d37edc1302ea08ee5ddb376befea.
Protocol details
Security review history
- OpenZeppelin View report
Evidence
- report Action Required: Critical Vulnerability (@AuctusOptions on X, 2022-03-29, via fxtwitter mirror) x.com
- code DeFiHackLabs: 20220326 Auctus - Arbitrary Call (README entry and Auctus_exp.sol) github.com
- analysis DeFiLlama defillama.com
- analysis Auctus Hack: Check If You're Affected (Revoke.cash) revoke.cash
- analysis auctus.org page auctus.org auctus.org
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.