Goose Finance Hack

TOTAL LOST $8K
Low Flash Loan Attacks bsc

What happened

In mid-March 2026, Goose Finance's BNB Chain StrategyGooseEgg contract was exploited for about $8,435. BlockSec attributed the incident to the order in which the strategy minted shares and accounted for harvested rewards.

Technical Root Cause

The strategy's share minting and reward-harvest accounting occurred in an unsafe order. Pending rewards were excluded when shares were created but included when shares were redeemed, allowing a user to capture value that should have been reflected in the deposit price.

Case & protocol details

Classification Token & Share Accounting / Protocol Logic
Protocol Type Farm
Smart Contract Language Solidity
Protocol Twitter/X @Goosedefi

Attack Timeline

The vulnerable flow minted a depositor's shares before incorporating pending harvested rewards into the strategy's asset value. A later withdrawal triggered reward harvesting, so the share price used for redemption included value that had not been reflected at mint time. BlockSec reported that the attacker paired this accounting asymmetry with flash-borrowed capital, repeatedly entering and exiting the strategy to obtain more value on withdrawal than was represented at deposit.

Even a small incident demonstrates a general vault risk: deposits, withdrawals, and reward realization must use a consistent asset-accounting order.

Security review history

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.