AutoShark Hack

TOTAL LOST $823K
Low Flash Loan Attacks bsc

What happened

On May 24, 2021, AutoShark Finance on BSC was exploited through its SHARK reward-minting logic. The attacker used a 100,000-WBNB flash swap to temporarily load SHARK and WBNB into SharkMinter, inflating its balance-based reward calculation. Calling getReward() minted 100 million SHARK, which was sold to repay the loan and leave roughly 2,213 WBNB in proceeds.

Technical Root Cause

SharkMinter's reward-mint calculation trusted manipulable contract balances rather than accounting isolated from arbitrary token transfers. An attacker could donate temporary SHARK and WBNB immediately before reward calculation, overstating profit and minting excessive rewards.

Case & protocol details

Classification Ecosystem / Exchange (DEX)
Protocol Type DEX
Affected asset / contract SHARK
Official Website autoshark.finance/
Protocol Twitter/X @AutoSharkFin

Attack Timeline

The attacker prepared a SHARK-BNB vault position, flash-borrowed 100,000 WBNB, swapped part for SHARK, and transferred SHARK plus WBNB to SharkMinter before triggering getReward(). Because the minter treated live balances as profit inputs, temporary balances inflated the computed LP amount and caused excessive SHARK issuance. The attacker sold the minted SHARK, repaid the flash loan, and retained the remaining WBNB.

Evidence & learning

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.