DFX Finance Hack
What happened
DFX Finance was exploited due to a flashloan vulnerability. The attacker siphoned off 4,445,279 $USD worth of assets, and an MEV bot was able to frontrun the hacker for the additional 3,200,000 $USD.
DFX Finance is a trading protocol providing flash loans. The attacker drained 4,445,279 $USD worth of assets in various tokens and transferred 2962 $ETH through Tornado Cash. 545,312 $USD worth of $CADC stays at the attacker's address, and 135,265 $USD worth of $TRYb remains at the malicious contract used for an attack.
The malicious actor exploited a known smart contract vulnerability that allows passing the balance check after a flashloan and gives approval of tokens to the attacker. The MEV bot was able to frontrun the hacker during token transfers for an additional 3,200,000 $USD in $USDC, $NZDS, $CADC, and $GYEN tokens. The DFX team claims that they are contacting the MEV bot owners to return the lost funds.
Attacker address:
https://etherscan.io/address/0x14c19962…b9a067
Malicious contract:
https://etherscan.io/address/0x6cfa86a3…41f22d
MEV bot:
https://etherscan.io/address/0xfde0d157…81455a
Malicious transactions list:
https://etherscan.io/txs?a=0x6cfa86a3…41f22d
Case & protocol details
Funds Recovery
Recovered
$205K
Net Loss
$7,438,861
Post-Incident Timeline
-
2022-11-19
The DFX Finance started a multi-phase recovering plan. The project already provided 2,000,000 $DFX tokens which are worth 204,800 $USD at the moment to help recover affected Liquidity Pools. The funds to be recovered were fully calculated and published.
Evidence & learning
Sources and on-chain records
- report Report theblock.co
- report Report twitter.com
- report Report twitter.com
- report Report twitter.com
- report Report docs.google.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.