AutoShark Hack
What happened
On May 24, 2021, AutoShark Finance on BSC was exploited through its SHARK reward-minting logic. The attacker used a 100,000-WBNB flash swap to temporarily load SHARK and WBNB into SharkMinter, inflating its balance-based reward calculation. Calling getReward() minted 100 million SHARK, which was sold to repay the loan and leave roughly 2,213 WBNB in proceeds.
SharkMinter's reward-mint calculation trusted manipulable contract balances rather than accounting isolated from arbitrary token transfers. An attacker could donate temporary SHARK and WBNB immediately before reward calculation, overstating profit and minting excessive rewards.
Case & protocol details
Attack Timeline
The attacker prepared a SHARK-BNB vault position, flash-borrowed 100,000 WBNB, swapped part for SHARK, and transferred SHARK plus WBNB to SharkMinter before triggering getReward(). Because the minter treated live balances as profit inputs, temporary balances inflated the computed LP amount and caused excessive SHARK issuance. The attacker sold the minted SHARK, repaid the flash loan, and retained the remaining WBNB.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report watchpug.medium.com
- report Post-mortem medium.com
- report Post-mortem rekt.news
- transaction Transaction bscscan.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.