DFX Finance Hack

TOTAL LOST $7.6M
Medium Other

What happened

DFX Finance was exploited due to a flashloan vulnerability. The attacker siphoned off 4,445,279 $USD worth of assets, and an MEV bot was able to frontrun the hacker for the additional 3,200,000 $USD.

DFX Finance is a trading protocol providing flash loans. The attacker drained 4,445,279 $USD worth of assets in various tokens and transferred 2962 $ETH through Tornado Cash. 545,312 $USD worth of $CADC stays at the attacker's address, and 135,265 $USD worth of $TRYb remains at the malicious contract used for an attack.

The malicious actor exploited a known smart contract vulnerability that allows passing the balance check after a flashloan and gives approval of tokens to the attacker. The MEV bot was able to frontrun the hacker during token transfers for an additional 3,200,000 $USD in $USDC, $NZDS, $CADC, and $GYEN tokens. The DFX team claims that they are contacting the MEV bot owners to return the lost funds.

Attacker address:

https://etherscan.io/address/0x14c19962…b9a067

Malicious contract:

https://etherscan.io/address/0x6cfa86a3…41f22d

MEV bot:

https://etherscan.io/address/0xfde0d157…81455a

Malicious transactions list:

https://etherscan.io/txs?a=0x6cfa86a3…41f22d

Case & protocol details

Classification Exchange (DEX)
Protocol Type Exploit/Other
Affected asset / contract DFX-XIDR-v2
Official Website dfx.finance/
Protocol Twitter/X @DFXFinance

Funds Recovery

2.7%

Recovered

$205K

Net Loss

$7,438,861

Post-Incident Timeline

  • 2022-11-19

    The DFX Finance started a multi-phase recovering plan. The project already provided 2,000,000 $DFX tokens which are worth 204,800 $USD at the moment to help recover affected Liquidity Pools. The funds to be recovered were fully calculated and published.

Evidence & learning

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.