EGD Finance Hack
What happened
On August 7, 2022, an attacker took about 36,044 USDT (BSC-USD) from EGD Finance, a staking protocol on BNB Chain, by manipulating the EGD/USDT PancakeSwap pool that the contract used to price its EGD rewards. BlockSec called it a typical price manipulation attack, and PeckShield reported that EGD fell about 20% afterwards.
The attacker had staked 100 USDT earlier to earn a small reward position. In the attack transaction they flash-borrowed nearly all the USDT in the EGD/USDT pool, which distorted the EGD price the staking contract read. Their reward claim then paid out 5,614,105 EGD, which they sold for USDT.
Attacker: 0xee0221d76504aec40f63ad7e36855eebf5ea5edd. Attack contract: 0xc30808d9373093fbfcec9e026457c6a9dab706a7. Attack tx: 0x50da0b1b6e34bce59769157df769eb45fa11efc7d0e292900d6b0a86ae66a2b3.
How it happened
- In an earlier transaction the attack contract bonded an inviter and staked 100 USDT in EGD Finance, starting to accrue rewards.
- In the attack transaction it flash-swapped 2,000 USDT from the PancakeSwap USDT/WBNB pool.
- Inside that callback it flash-swapped about 424,456 USDT, nearly the entire USDT reserve, from the EGD/USDT pool.
- With the pool's USDT almost gone, the EGD price read by
getEGDPrice()was badly distorted, andclaimAllReward()paid the contract 5,614,105 EGD. - The attacker repaid both flash swaps plus fees, sold the EGD for USDT, and kept about 36,044 USDT.
Protocol details
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.