Bloom Hack

TOTAL LOST $540K
Low Accounting blast

What happened

Bloom, a Blast perpetuals DEX built around rebasing USDB collateral, was exploited on May 9, 2024 through a margin-accounting bug. The protocol later reported $540K exploited and $486K recovered after a negotiated 10% bounty.

Technical Root Cause

The flaw was stale yield-accounting state, not a token-level rebasing defect. The margin-update flow failed to consume or correctly checkpoint accrued yield when negative-PnL positions withdrew collateral, allowing duplicate withdrawal of the same yield entitlement.

Case & protocol details

Classification Protocol Logic
Protocol Type RWA
Smart Contract Language Solidity
Official Website www.bloom.trading/
Protocol Twitter/X @BloomOnBlast

Attack Timeline

Bloom credited pending Blast-native yield to trading positions. During a cash deposit or withdrawal, updateTrade should have advanced the checkpoint used to calculate that yield. For negative-PnL positions, the checkpoint timestamp was not updated correctly.

An attacker could repeatedly use UpdateMargin to withdraw USDB-equivalent value for yield that had already been accounted for.

Funds Recovery

90.0%

Recovered

$486K

Net Loss

$54,000

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.