Blizzard Hack
Incident Overview
The insider attack was performed by 2 team members: front-end and back-end developers.
Developers had access to the key contracts as they were members of a multisignature account, which requires only 2 signs.
1. Whitehat reported found bug in the vault contracts to the Immunefi team
2. Whitehat received bug bounty and the core team of Blizzard asked the back-end developer to remove retired vaults, put 0 reward rate and disable deposits.
3. Front-end and back-end started testing new vaults:
https://snowtrace.io/tx/0xf66a695d…f3f48e
4. Back-end dev set the rewardMintRate to 50 BLIZZ per block
5. Developers exploited the harvesting issue:
https://snowtrace.io/tx/0xa7818cb8…4b0363
6. Front-end dev had removed the retired PNG-AVAX vaults from the website front.
7. Developers exploited a single USDC vault:
https://snowtrace.io/address/0xdb696940…49b64e#code
8. Developers dumped received tokens:
https://snowtrace.io/tx/0x7cd6c8c8…00e482
9. Attackers used Anyswap bridge to transfer funds on Ethereum, and then, on the Binance Smart Chain
https://snowtrace.io/tx/0x198c7303…111495
10. Stolen funds were deposited into Tornado Cash mixer at:
https://explorer.bitquery.io/bsc/txs/transfers?sender=0xbb2c0ef4…2ea965¤cy=BNB&receiver=0x0d5550d5…859b17
The exploit is described in 3 steps:
- Modify the rewardRate, by calling setRewardMintRate(uint256 _rate) with the following parameter: 50000000000000000000
- Deposit any amount of USDC and wait until the desired amount of tokens has been minted
- Call claim() to transfer the rewards from the origin pool and additional minted token rewards from the aggregator to the beneficiary.
Incident Report
Protocol Information
Market Context at Time of Hack
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Blizzard, these are the critical security checks that could have prevented this incident (November 2021).
- Verify all logic paths related to Other are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
Learn to Prevent the Next Blizzard
The Blizzard hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.