FilDA Hack
What happened
On April 12th, 2022, an exploit occurred on FilDA resulting in compromised funds of up to $2 million. The dev team has identified the root cause and suspended all deposits and borrowing on FilDA-ESC. FilDA contracts on other chains remain unaffected.
The compromised funds amount to around 1.6 million USD and were mainly in the form of USDC, HUSD, BUSD, BTC, and ETH. The root cause of the issue is due to the protocol's inability to handle flashloans of ERC677 tokens properly. The attacker used a flashloan to borrow the underlying token, which was then deposited into the protocol via a callback function controlled by the attacker.
This resulted in lots of extra f tokens being minted. The borrowed token was then returned to the protocol via a flashloan callback, but lots of fTokens were left to the attacker, allowing them to redeem most of the cash in the lending pool. FilDA on other chains is not affected since the issue is only related to ERC677 tokens.
Attacker Address: 0x4a9a0cC1…858874
Money Laundering address: 0x93c3A805…6a4d74
Attacker contract: 0x00Ff915E…D05BC3
Case & protocol details
Funds Recovery
Recovered
$229K
Net Loss
$1,770,000
Post-Incident Timeline
-
2023-04-24
Filda Team announced about returning funds. 160,000 $ELO and 21,000 $DAI were returned which is worth 229,000 $USD in total at the moment.
Evidence & learning
Sources and on-chain records
- report Report fildafinance.medium.com
- report Report twitter.com
- analysis Web Archive archive.ph
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.