Elephant Money Hack

TOTAL LOST $22.2M
High Flash Loan Attacks BNB Chain

What happened

On April 12, 2022, an attacker used flash liquidity to manipulate ELEPHANT's spot price during TRUNK stablecoin minting and redemption. The inflated valuation allowed the attacker to extract assets from Elephant Money's BUSD and ELEPHANT treasuries.

Technical Root Cause

The TRUNK mint and redemption path relied on the instantaneous ELEPHANT/WBNB pool price. Its internal purchase flow created a feedback loop that let temporary price manipulation affect minting and redemption values.

Case & protocol details

Classification Oracle Manipulation / Flash Loan
Protocol Type Yield
Affected asset / contract ELEPHANT
Smart Contract Language Solidity
Official Website elephant.money/
Protocol Twitter/X @ElephantStatus

Attack Timeline

The attacker borrowed about 131,000 WBNB and 91 million BUSD, bought ELEPHANT to distort the ELEPHANT/WBNB pool, and minted TRUNK with BUSD. The mint path itself converted BUSD to WBNB and bought ELEPHANT, amplifying the manipulated spot price. The attacker then sold ELEPHANT at the inflated price and redeemed TRUNK for WBNB and BUSD before repaying the flash loans.

Security review history

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.