Cover Protocol Hack
What happened
Cover Protocol's Blacksmith reward-mining contract was exploited on December 28, 2020 at 08:08 UTC. The core coverage product was not affected. The flaw let attackers mint unearned COVER rewards through stale reward-accounting state, causing about $9.4 million in damage.
Grap Finance returned 4,351 ETH, which Cover reported as about 34% of the total damage.
Reward debt was calculated from a stale in-memory pool snapshot after the authoritative storage state had been updated. Near-empty pools made the resulting accounting mismatch arbitrarily large. Staking-reward systems must preserve accounting invariants across deposit, withdrawal, and claim sequences, especially with one-wei residual balances, and must not compute user writeoffs from stale pool state.
Case & protocol details
Attack Timeline
Blacksmith's deposit() copied a Pool struct to memory before updatePool() updated the storage-side accRewardsPerToken. It then calculated the depositor's rewardWriteoff from the stale memory copy. Attackers amplified the gap by reducing a pool's LP balance to nearly zero, redepositing, and triggering the reward calculation.
The updated accumulator rose sharply because the denominator was tiny while the account writeoff remained too small. Grap Finance left one wei in its pool before redepositing, minted an enormous amount of COVER through the discrepancy, sold part of it, burned the remainder, and returned 4,351 ETH. Cover removed Blacksmith's minting rights to stop the exploit.
Funds Recovery
Recovered
$3.2M
Net Loss
$6,204,000
Evidence & learning
Proof of concept
1 availableSources and on-chain records
- report Post-Mortem slowmist.medium.com
- report Report coverprotocol.medium.com
- report Post-mortem rekt.news
- report Post-mortem rekt.news
- transaction Transaction etherscan.io
- code Code reference github.com
- analysis Website reference mudit.blog
- analysis Website reference notion.so
- analysis PeckShield Cover unlimited-mint analysis peckshield.medium.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.