Carol Protocol Hack

TOTAL LOST $61K
Low Flash Loan Attacks

What happened

Carol Protocol suffers flash loan exploit, resulting in a loss of $61,164 USD (29.92 ETH).

On November 30th, 2023, Carol Protocol, a project running on the Base chain, experienced a flash loan exploit due to a smart contract vulnerability. The root cause of this exploit was identified as manipulation of the stake amount. The contract's design flaw lies in its reliance on Uniswap Pair Balance to determine user balances, a metric that is susceptible to manipulation.

The stolen funds were distributed between multiple addresses and then transferred to another scammer's EOA. The total loss amounted to $61,164 USD, equivalent to 29.92 ETH.

Binance Smart Chain:

Attacker address:

https://basescan.org/address/0x5AA27D55…bC3144

Funds Holder as of Dec 14, 2023:

https://basescan.org/address/0xcDd37Ada…4A2af2

Malicious transactions:

https://basescan.org/tx/0xd962d397…b4185c

Malicious contract:

https://basescan.org/address/0xc4566ae9…780b2c

Case & protocol details

Classification Other
Protocol Type Exploit/Flash Loan Attack
Affected asset / contract CAROL
Official Website carol.finance/bonding
Protocol Twitter/X @carolprotocol

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.