flash.sx / vaults.sx Hack

Reported loss $13.0M
EOS
Reentrancy

What happened

On May 14, 2021, a reentrancy exploit drained approximately 1.18 million EOS and 462,000 USDT from vaults.sx. The attacker used EOSIO action ordering to redeem shares against stale balance accounting. EOS block producers froze assets distributed across 246 accounts; the EOS Network Foundation later reported that users were made whole.

Technical root cause

The vault refreshed its accounting before a queued token transfer completed. EOSIO notification and inline-action ordering allowed stale balances to determine later redemption payouts.

How it happened

  1. The attacker deposited assets and received SX shares, then began redeeming part of them.
  2. Transfer notifications queued further actions, including a small flash.sx loan that triggered a vault balance update.
  3. The update read the token balance before the pending redemption transfer executed, overwriting the reduced internal balance with stale data.
  4. A second redemption used the inflated accounting and paid more than the correct share. Repeating the sequence drained the vault.

Protocol details

Classification Reentrancy
Protocol Type DeFi Protocol
Implementation language C++

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.