Elephant Money Hack
What happened
On April 12, 2022, an attacker used flash liquidity to manipulate ELEPHANT's spot price during TRUNK stablecoin minting and redemption. The inflated valuation allowed the attacker to extract assets from Elephant Money's BUSD and ELEPHANT treasuries.
The TRUNK mint and redemption path relied on the instantaneous ELEPHANT/WBNB pool price. Its internal purchase flow created a feedback loop that let temporary price manipulation affect minting and redemption values.
Case & protocol details
Attack Timeline
The attacker borrowed about 131,000 WBNB and 91 million BUSD, bought ELEPHANT to distort the ELEPHANT/WBNB pool, and minted TRUNK with BUSD. The mint path itself converted BUSD to WBNB and bought ELEPHANT, amplifying the manipulated spot price. The attacker then sold ELEPHANT at the inflated price and redeemed TRUNK for WBNB and BUSD before repaying the flash loans.
Evidence & learning
Sources and on-chain records
- report Report twitter.com
- report Post-mortem medium.com
- report Post-mortem rekt.news
- analysis Website reference twitter.com
- analysis Website reference twitter.com
- analysis Elephant Money Hack: April 12, 2022 Detailed Analysis immunebytes.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.