flash.sx / vaults.sx Hack
What happened
On May 14, 2021, a reentrancy exploit drained approximately 1.18 million EOS and 462,000 USDT from vaults.sx. The attacker used EOSIO action ordering to redeem shares against stale balance accounting. EOS block producers froze assets distributed across 246 accounts; the EOS Network Foundation later reported that users were made whole.
The vault refreshed its accounting before a queued token transfer completed. EOSIO notification and inline-action ordering allowed stale balances to determine later redemption payouts.
How it happened
- The attacker deposited assets and received SX shares, then began redeeming part of them.
- Transfer notifications queued further actions, including a small flash.sx loan that triggered a vault balance update.
- The update read the token balance before the pending redemption transfer executed, overwriting the reduced internal balance with stale data.
- A second redemption used the inflated accounting and paid more than the correct share. Repeating the sequence drained the vault.
Protocol details
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.