Cashio Hack
What happened
On March 23, 2022, Cashio's Solana stablecoin minting program was exploited after it accepted attacker-created account data as valid collateral configuration. The attacker minted billions of unbacked CASH and drained the collateral backing the system, with reports placing the loss at about $52.8 million.
The Brrr minting program failed to verify that the supplied Bank account and collateral configuration were the protocol's authorized program-derived accounts. That let a caller substitute fake accounts and satisfy local consistency checks without depositing real collateral.
Case & protocol details
Attack Timeline
Cashio's print_cash instruction received a Bank account, collateral account, and Saber-related accounts supplied by the caller. The program checked only their relationship to one another, not that they belonged to Cashio's authorized configuration. The attacker created matching fake accounts, passed them into the minting instruction, minted unbacked CASH, then redeemed and sold it against genuine collateral.
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.