Bloom Hack
What happened
Bloom, a Blast perpetuals DEX built around rebasing USDB collateral, was exploited on May 9, 2024 through a margin-accounting bug. The protocol later reported $540K exploited and $486K recovered after a negotiated 10% bounty.
The flaw was stale yield-accounting state, not a token-level rebasing defect. The margin-update flow failed to consume or correctly checkpoint accrued yield when negative-PnL positions withdrew collateral, allowing duplicate withdrawal of the same yield entitlement.
Case & protocol details
Attack Timeline
Bloom credited pending Blast-native yield to trading positions. During a cash deposit or withdrawal, updateTrade should have advanced the checkpoint used to calculate that yield. For negative-PnL positions, the checkpoint timestamp was not updated correctly.
An attacker could repeatedly use UpdateMargin to withdraw USDB-equivalent value for yield that had already been accounted for.
Funds Recovery
Recovered
$486K
Net Loss
$54,000
Evidence & learning
Sources and on-chain records
- report Report twitter.com
- report Report twitter.com
- report Report twitter.com
- report Post-mortem mirror.xyz
- report Bloom recovery report chaincatcher.com
- analysis Quadriga Bloom incident archive quadrigainitiative.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.