ChiSale Hack

Reported loss $16K
Ethereum
Unknown

What happened

On November 7, 2024 an attacker drained about $16,300 in ETH from ChiSale, an old Ethereum contract that sold CHI tokens with a referral payout. TenArmor traced the bug to the buy function, which calculated the referrer's reward from msg.value instead of the ETH actually spent on tokens. When a buyer sent more ETH than the remaining tokens cost, the contract refunded the excess but still paid the referral share on the full amount. Using a Balancer flash loan, the attacker named its own contract as referrer and sent far more ETH than the purchase needed, collecting both the refund and an oversized referral payment.

Attack tx: 0x586a2a4368a1a45489a8a9b4273509b524b672c33e6c544d2682771b44f05e87

How it happened

  1. The attacker flash-borrowed 25,000 WETH from Balancer, unwrapped it to ETH and received it in an attack contract.
  2. A helper contract bought about 2,456,112 CHI from ChiSale for about 1,993.5 ETH, naming the attack contract as referrer. ChiSale paid the referrer about 438.6 ETH.
  3. The attack contract then called buy with about 18,457.75 ETH while naming itself as referrer. Only about 32,505 CHI could be bought, so ChiSale refunded about 15,957.75 ETH as the unused remainder.
  4. ChiSale still paid the referral share on the full msg.value, sending about 4,060.7 ETH back to the attack contract. That is far more than the share of the roughly 2,500 ETH actually spent.
  5. The attacker rewrapped and repaid the 25,000 WETH and kept about 5.78 ETH (around $16,300) plus the CHI it had bought.

Protocol details

Classification Protocol Logic
Protocol Type DeFi Protocol
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.