Brahma Finance Hack

TOTAL LOST $90K
Low Access Control Attacks ethereum

What happened

Brahma protocol was exploited due to the smart contract vulnerability. The attacker drained user funds for 89,522 $USD.

Brahma Finance is a crosschain yield and hedge protocol. The project's Zapper contract was exploited via smart contract vulnerability. The attacker used the deployed unverified smart contract to exploit the logic of the Zapper contract to drain $USDC from three users.

The stolen amount of 89,522 $USDC was swapped to $DAI and remains at the attacker's original address at the moment.

Attacker address:

https://etherscan.io/address/0x6fa00a73…4c4213

Malicious transaction:

https://etherscan.io/tx/0xeaef2831…6f29c0

Malicious contract:

https://etherscan.io/address/0x60032a41…895c05#code

Swap transaction:

https://etherscan.io/tx/0x4249331d…4181a0

Case & protocol details

Classification Exchange (DEX),Yield Aggregator / Access Control
Protocol Type Exploit/Other
Affected asset / contract brahTOPG
Smart Contract Language Solidity
Official Website www.brahma.fi/
Protocol Twitter/X @brahmafi?lang=en

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.