Cashio Hack
Incident Overview
Cashio protocol was exploited due to incorrect collateral validation during minting, which has led to infinite minting.
The validation of the LP tokens is to be deposited via the saber_swap.arrow (USDT-USDC LP) is incomplete, as the mint field is never validated. As a consequence, the hacker was able to deploy a bogus contract that was never verified, followed by a chain of bogus accounts that all passed validation since they were only compared to one another.
In addition, in order to pass the common collateral verification, the hacker created a fake bank and was able to instruct the program to mint the original $CASH token because there was no check that the bank's token matched the one being minted.
After these actions, the hacker minted 2 billion $CASH tokens, and the part of $CASH was burnt to SaberLPTokens. Then another part of the tokens was withdrawn out to $UST and $USDC. The remaining $CASH was swapped for 8,600,000 $UST and 17,000,000 $USDC. Most of the stolen funds were bridged to Ethereum address.
The hacker left the message in the transaction "Account with less than 100k have been returned. All other money will be donated to charity."
The hacker's address:
https://solscan.io/account/6D7fgzpPZX…hnVuzw
Validation transaction:
https://solscan.io/tx/3t1zqtKk4C…Y2Z39y
Mint transaction:
https://solscan.io/tx/2X1TKidhbo…P6H5tP
Burning to SaberLPTokens transaction:
https://solscan.io/tx/4g5okypEDK…9QrUvV
Withdraw transaction:
https://solscan.io/tx/pjUgAeUfWa…vbsrwH
Ethereum address funds were sent:
https://etherscan.io/address/0x86766247ba3405c5f15f06b895294200809e9cfb
The message hacker left:
https://etherscan.io/tx/0xa8394d2e55042f84d096c72dd1075fa2648faf88e248c7992273b4d50a6a647b
Incident Report
Protocol Information
Market Context at Time of Hack
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Cashio, these are the critical security checks that could have prevented this incident (March 2022).
- Verify all logic paths related to Collateral Validation Exploit / Other are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSources & References
Learn to Prevent the Next Cashio
The Cashio hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.