Bacon Protocol Hack

TOTAL LOST $1.0M
Medium Flash Loan Attacks ethereum

What happened

The exploiter's address:

https://etherscan.io/address/0x7c42f2a7…607593

The transaction behind the exploit:

https://etherscan.io/tx/0x7d2296bc…dbcf31

The hack is made possible due to a reentrancy bug in the lend() routine so that the exploiter can get more lending credits via re-entering the lend() routine.

The contract exploit led to sending 957,166 USDC out of the protocol. A second exploit was prevented by a white hat group who returned the 34,232 USDC they received. These changes caused the price of bHOME to temporarily unpeg and decrease to $0.86.

As of March 6th, the BaconCoin team has deposited 991,441 USDC into the BaconCoin multi-sig that will be used to recapitalize the protocol:

https://etherscan.io/tx/0xf13823ec…bdcdc7

https://etherscan.io/tx/0x23ccdd96…8dc668

Case & protocol details

Classification Other / Reentrancy
Protocol Type Exploit/Flash Loan Attack
Affected asset / contract bHOME
Smart Contract Language Solidity
Official Website www.baconcoin.com/
Protocol Twitter/X @BaconProtocol

Funds Recovery

95.7%

Recovered

$957K

Net Loss

$43,000

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.