Goose Finance Hack
What happened
In mid-March 2026, Goose Finance's BNB Chain StrategyGooseEgg contract was exploited for about $8,435. BlockSec attributed the incident to the order in which the strategy minted shares and accounted for harvested rewards.
The strategy's share minting and reward-harvest accounting occurred in an unsafe order. Pending rewards were excluded when shares were created but included when shares were redeemed, allowing a user to capture value that should have been reflected in the deposit price.
Case & protocol details
Attack Timeline
The vulnerable flow minted a depositor's shares before incorporating pending harvested rewards into the strategy's asset value. A later withdrawal triggered reward harvesting, so the share price used for redemption included value that had not been reflected at mint time. BlockSec reported that the attacker paired this accounting asymmetry with flash-borrowed capital, repeatedly entering and exiting the strategy to obtain more value on withdrawal than was represented at deposit.
Even a small incident demonstrates a general vault risk: deposits, withdrawals, and reward realization must use a consistent asset-accounting order.
Security review history
- CertiK Report
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.