Belt Finance Hack

TOTAL LOST $6.3M
Medium Flash Loan Attacks bsc

What happened

On 29 May 2021, an attacker used PancakeSwap flash loans to manipulate Belt Finance's multi-strategy BUSD vault accounting on BNB Smart Chain. By temporarily skewing the Ellipsis BUSD/USDT balance, the attacker caused Belt's beltBUSD share valuation to overstate vault value, then withdrew excess BUSD from the Venus strategy. Belt reported 6,234,753 BUSD in attacker profit; this is distinct from a broader pool-accounting figure reported at the time.

Technical Root Cause

The vault's share-value and redemption calculations trusted strategy balances that could be distorted atomically with flash-loaned capital. A multi-strategy vault must account safely for adversarial intermediate states rather than treating temporarily manipulated pool balances as settled value.

Case & protocol details

Classification Yield Aggregator / Protocol Logic / Share Accounting
Protocol Type Yield
Affected asset / contract BELT
Smart Contract Language Solidity
Official Website belt.fi/
Protocol Twitter/X @BELT_Finance

Attack Timeline

The attacker used large PancakeSwap flash loans to alter the balance of Belt's underlying Ellipsis strategy in a single transaction. Belt's multi-strategy vault treated the temporarily distorted strategy balance as reliable when calculating the value of beltBUSD shares. With that share value overstated, the attacker could redeem more BUSD from the Venus strategy than the position should have supported.

Public incident reconstructions describe repeated loops: deposit into the strategies, skew the Ellipsis BUSD/USDT pool, withdraw against the inflated valuation, restore the balance, and repeat before repaying the flash loans. The core failure was manipulable vault-share and redemption accounting, not a compromise of an external price feed.

Security review history

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.