Beluga Hack
What happened
On 13 October 2023 an attacker took about $175,000 from Beluga, a multichain stableswap AMM, through its USDT/USDC.e pool on Arbitrum. CertiK reported a flash-loan attack spread over 21 transactions: the attacker manipulated the pool's USDT and USDC.e balances so that it could withdraw more tokens than it had deposited. PeckShield put the haul at about 113 ETH. The exploiter's address had been funded with 0.1 ETH from OKX, and the proceeds were later moved to the MEXC exchange. No Beluga statement or compensation plan was found.
Attacker: 0x4843e00ef4c9f9f6e6ae8d7b0a787f1c60050b01. Example attack transaction: 0x57c96e320a3b885fabd95dd476d43c0d0fb10500d940d9594d4a458471a87abe.
How it happened
- The attacker flash-borrowed large amounts of USDT and USDC.e from the Balancer vault.
- In each round they deposited both tokens into the Beluga pool and made a large swap, shifting the balance between the two assets.
- They then withdrew their liquidity from the side the swap had shifted in their favour, and swapped back, getting out more than they had put in.
- After repeating the loop, they repaid the flash loan and swapped the profit to ETH on SushiSwap. Across 21 transactions, about $175K left the pool.
Protocol details
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.