DualPools Hack

TOTAL LOST $41K
Low Flash Loan Attacks bsc

What happened

DualPools DeFi project was exploited via a smart contract vulnerability, resulting in a loss of 41,286 $USD.

DualPools, a DeFi project offering Swap, Lend, and Borrow services, was exploited on February 15, 2024. The attacker manipulated the price of dLINK by exploiting insufficient liquidity in a new DualPools pool and depleted targeted assets (WBNB, BTC, ETH, ADA, BUSD) from other pools through the borrow function. Additionally, the attacker exploited a precision truncation issue in the smart contract division, reclaiming all previously invested LINK.

The stolen funds were swapped to BNB, transferred to another EOA, and then after a week deposited into the TornadoCash .

Attacker Address:

https://bscscan.com/address/0x46458632…37D66C

Additional Attacker's Address:

https://bscscan.com/address/0x7F27C9ed…826616

Malicious Transaction:

https://bscscan.com/tx/0x90f374ca…ef1e93

Malicious Contract Address:

https://bscscan.com/address/0x38721b0d…A7200E

TornadoCash Deposit Transactions:

https://bscscan.com/tx/0xcedff18c…b741c2

https://bscscan.com/tx/0x7de2a931…aa24ec

Case & protocol details

Classification Borrowing and Lending / Token & Share Accounting
Protocol Type Exploit/Flash Loan Attack
Affected asset / contract dLINK
Smart Contract Language Solidity
Protocol Twitter/X @dualpools

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.