Exactly Hack

TOTAL LOST $7.6M
Medium Access Control Attacks optimism

What happened

Exactly Protocol suffered a reentrancy attack, resulting in the loss of 4332.92 ETH, valued at approximately 7,197,240 $USD.

On August 18, 2023, Exactly Protocol, a lending and borrowing protocol operating on the Optimism chain, was exploited through a reentrancy attack. The attacker bypassed the permit check in the DebtManager contract's leverage function by using a fake market address without validation and changing the msg.sender to the victim's address. They then reentered the crossDeleverage function and stole the collaterals.

The stolen funds, a total of 4332.92 ETH, were bridged to the Ethereum mainnet, partly through the Across Protocol and partly via the Optimism Bridge. The value of the loss was approximately 7,197,240 $USD.

The Exactly:Deployer sent an on-chain message to the exploiter, expressing willingness to discuss the incident and providing instructions for private communication.

Optimism:

Attacker Addresses:

  1. Address
  2. Address

Malicious Transactions:

  1. Tx
  2. Tx
  3. Tx

Malicious Contract:

https://optimistic.etherscan.io/address/0x6dd61c69…1a5b4d

Bridging Transaction:

https://optimistic.etherscan.io/tx/0x27f0fd95…8b8a31

Ethereum:

Funds Holder:

https://etherscan.io/address/0xE4f34a72…9da042

Bridging Transaction:

https://etherscan.io/tx/0x77461e80…826849

Onchain Message:

https://etherscan.io/tx/0x91dd9c55…2fe3d1

Case & protocol details

Classification Protocol Logic / Access Control / Borrowing and Lending
Protocol Type Lending
Affected asset / contract EXA
Smart Contract Language Solidity
Official Website exact.ly/
Protocol Twitter/X @ExactlyProtocol

Security review history

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.