Health Hack
What happened
Price of the HEALTH token in a Uniswap pool was manipulated allowing the attacker to take a 33 BNB profit.
The exploit was possible due to a bug in the internal _tranfer() function of the token contract that was causing decrease of HEALTH in the pool.
The attack was performed in three transactions. Each transaction involved the following steps:
- Taking a flash loan of 40 WBNB;
- Exchanging the borrowed amount to HEALTH;
- Calling 999 token transfers with 0 value. Due to the bug in _transfer(), the number of HEALTH in the pool decreased each time, hence the token price was increasing.
- Exchanging the inflated HEALTH token to WBNB with profit.
- Paying back the flashloan
The attacker contract:
https://bscscan.com/address/0x80e5fc0d…1ea2d4
The attack transactions:
https://bscscan.com/tx/0xae8ca9dc…c66ccf
https://bscscan.com/tx/0x780f7128…e0266a
https://bscscan.com/tx/0x0daad55e…a3a462
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report blog.solidityscan.com
- report Report twitter.com
- analysis Web Archive archive.ph
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.