Cauldron Hack
Incident Overview
The biggest flash loan attack on Avalanche in 2022 was detected. The attacker took 370,000 $USD after interacting with several assets.
The attacker interacted with Cauldron, Aave, JoeSwap, and Curve for various purposes. The attacker used a malicious smart contract with an unverified source code to withdraw 998,000 $nxUSD using LP tokens worth 500,000 $USDC. The full attack flow of the exploit transaction succeeded as follows:
1. The attackers malicious contract flashloaned 51,000,000 $USDC from Aave
2. 280,000 $USDC were swapped to $WAVAX with JoeSwap
3. liquidity was added using claimed $WAVAX and 260,000 $USDC so 0.0045 JoeLPToken was received
4. The remaining 50,460,000 $USDC were swapped for $WAVAX on JoeSwap and it changed the reserve of the pool
5. The attackers contract called the updateExchangeRate function on the CauldronV2 smart contract, which changed the ExchangeRate variable according to the previous JoeSwap pool's reserve amount
6. The attackers contract deposited 0.0045 JoeLPToken to the CauldronV2 and 998,000 $nxUSD were withdrawn from DegenBox. Because of the manipulated ExchangeRate variable, the attacker was able to take that amount for 500,000 $USD worth JoeLPTokens
7. The remaining $WAVAX were swapped back for 50,426,896 $USDC on the previous JoeSwap pool
8. Consequently, Curve.fi and other pools were used to swap 998,000 $nxUSD for 970,010 $USDC
9. The 51,025,500 $USDC for the flash loan were paid back to Aave
10. The profit amounted to 371,406 $USDC and were transferred to an EOA address.
CauldronV2 vulnerable contract:
https://snowtrace.io/address/0xe767c6c3…c4c060
Exploit transaction:
https://snowtrace.io/tx/0x0ab12913…54c026
Attacker address:
https://snowtrace.io/address/0x69992a2e…a0b1af
Attacker smart contract:
https://snowtrace.io/address/0x16b94c63…6e49d6
DegenBox contract:
https://snowtrace.io/address/0x0b1f9c22…59b775
Stolen funds sent to:
https://snowtrace.io/address/0x8ec74e6f…378381
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Cauldron, these are the critical security checks that could have prevented this incident (September 2022).
- Verify all logic paths related to Flash Loan Attack are guarded by proper access controls and input validation - see the Flash Loans Attacks attack class for patterns
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialRelated Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Sources & References
-
01
Source 1 https://archive.is/TiUzv
-
02
Source 2 https://archive.is/Rt3Up
Learn to Prevent the Next Cauldron
The Cauldron hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.