Blizzard Hack
What happened
The insider attack was performed by 2 team members: front-end and back-end developers.
Developers had access to the key contracts as they were members of a multisignature account, which requires only 2 signs.
- Whitehat reported found bug in the vault contracts to the Immunefi team
- Whitehat received bug bounty and the core team of Blizzard asked the back-end developer to remove retired vaults, put 0 reward rate and disable deposits.
- Front-end and back-end started testing new vaults:
https://snowtrace.io/tx/0xf66a695d…f3f48e
- Back-end dev set the rewardMintRate to 50 BLIZZ per block
- Developers exploited the harvesting issue:
https://snowtrace.io/tx/0xa7818cb8…4b0363
- Front-end dev had removed the retired PNG-AVAX vaults from the website front.
- Developers exploited a single USDC vault:
https://snowtrace.io/address/0xdb696940…49b64e#code
8. Developers dumped received tokens:
https://snowtrace.io/tx/0x7cd6c8c8…00e482
9. Attackers used Anyswap bridge to transfer funds on Ethereum, and then, on the Binance Smart Chain
https://snowtrace.io/tx/0x198c7303…111495
10. Stolen funds were deposited into Tornado Cash mixer at:
https://explorer.bitquery.io/bsc/txs/transfers?sender=0xbb2c0ef4…2ea965¤cy=BNB&receiver=0x0d5550d5…859b17
The exploit is described in 3 steps:
- Modify the rewardRate, by calling setRewardMintRate(uint256 _rate) with the following parameter: 50000000000000000000
- Deposit any amount of USDC and wait until the desired amount of tokens has been minted
- Call claim() to transfer the rewards from the origin pool and additional minted token rewards from the aggregator to the beneficiary.
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Post-mortem medium.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.