Compounder Finance Hack
What happened
Contract deployer exploited StrategyController smart contract, transferring funds to his wallet and hiding traces using Tornado Cash mixer.
The contract deployer exploited the StrategyController smart contract by invoking the inCaseTokensGetStuck() function. This allowed him to transfer funds directly into his wallet. The exploit was carried out in several transactions.
After acquiring the funds, the attacker used the Tornado Cash mixer to hide the traces of the stolen funds. This method of obscuring the origin of funds makes it difficult to track the attacker.
Malicious Transactions:
https://etherscan.io/tx/0x57c61df9…3fc7fe
https://etherscan.io/tx/0x10d245e6…113d77
https://etherscan.io/tx/0x0763afe2…901822
https://etherscan.io/tx/0xf94de5a0…f033e6
https://etherscan.io/tx/0x18e0efca…0cacfa
https://etherscan.io/tx/0x744c51b4…d852e5
https://etherscan.io/tx/0x9c75f706…809056
Tornado Cash Mixer Transaction:
https://bloxy.info/txs/calls_from/0x079667f4…1f0758?signature_id=11062&smart_contract_address_bin=0xa160cdab…53f291
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Post-mortem rekt.news
- analysis Web Archive web.archive.org
- analysis Website reference twitter.com
- analysis Website reference twitter.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.