Bacon Protocol Hack
What happened
The exploiter's address:
https://etherscan.io/address/0x7c42f2a7…607593
The transaction behind the exploit:
https://etherscan.io/tx/0x7d2296bc…dbcf31
The hack is made possible due to a reentrancy bug in the lend() routine so that the exploiter can get more lending credits via re-entering the lend() routine.
The contract exploit led to sending 957,166 USDC out of the protocol. A second exploit was prevented by a white hat group who returned the 34,232 USDC they received. These changes caused the price of bHOME to temporarily unpeg and decrease to $0.86.
As of March 6th, the BaconCoin team has deposited 991,441 USDC into the BaconCoin multi-sig that will be used to recapitalize the protocol:
https://etherscan.io/tx/0xf13823ec…bdcdc7
https://etherscan.io/tx/0x23ccdd96…8dc668
Case & protocol details
Funds Recovery
Recovered
$957K
Net Loss
$43,000
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report twitter.com
- report Report twitter.com
- report Report twitter.com
- report Post-mortem mirror.xyz
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.