Cashio Hack

TOTAL LOST $52.8M
High Access Control Attacks Solana

What happened

On March 23, 2022, Cashio's Solana stablecoin minting program was exploited after it accepted attacker-created account data as valid collateral configuration. The attacker minted billions of unbacked CASH and drained the collateral backing the system, with reports placing the loss at about $52.8 million.

Technical Root Cause

The Brrr minting program failed to verify that the supplied Bank account and collateral configuration were the protocol's authorized program-derived accounts. That let a caller substitute fake accounts and satisfy local consistency checks without depositing real collateral.

Case & protocol details

Classification Stablecoin minting / account validation failure
Protocol Type CDP
Affected asset / contract CASH
Smart Contract Language Rust
Official Website cashio.app/
Protocol Twitter/X @CashioApp

Attack Timeline

Cashio's print_cash instruction received a Bank account, collateral account, and Saber-related accounts supplied by the caller. The program checked only their relationship to one another, not that they belonged to Cashio's authorized configuration. The attacker created matching fake accounts, passed them into the minting instruction, minted unbacked CASH, then redeemed and sold it against genuine collateral.

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.