Hundred Finance Hack
Incident Overview
Hundred Finance was hacked due to a price manipulation attack, resulting in 6,701,157 $USD worth of cryptocurrency being drained from various pools.
Hundred Finance is a multichain lending protocol. The protocol experienced a hack due to a price manipulation attack on the Optimism layer-two chain. The attacker deployed malicious smart contract with unverified source code, and then donated 200 $WBTC to inflate hWBTC's exchange rate so that even a tiny amount (2 wei) of $hWBTC could drain current lending pools.
The attacker then borrows 500 $WBTC from Aave and deposited into the pool and borrowed funds from all pools because of the inflated price of $hWBTC. Consequently, 500 $WTBC was redeemed back for nothing, which caused the attacker contract being liquidated. This resulted in 6,701,157 $USD worth of cryptocurrency being drained from their lending pools.
The hacker bridged over 1,034 $ETH valued at 2,180,000 $USD on the day of transfer along with other cryptocurrencies such as USDC and USDT via Multichain and swapped them for various tokens including DAI, FRAX, PAXG among others. 919,224 $USD worth of $sUSD and $SNX remains at the attackers original address at the moment.
Attacker address:
https://optimistic.etherscan.io/address/0x155da45d…e67528
Malicious transactions:
https://optimistic.etherscan.io/tx/0x6e9ebcde…04f451
https://optimistic.etherscan.io//tx/0x15096dc6…ceea93
Malicious contracts:
https://optimistic.etherscan.io/address/0x978d0ce2…754982
https://optimistic.etherscan.io/address/0x284abd14…5c9aac
https://optimistic.etherscan.io/address/0xd340f220…1e702b
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Hundred Finance, these are the critical security checks that could have prevented this incident (April 2023).
- Verify all logic paths related to Flashloan Donate Function Logic Exploit / Oracle Issue are guarded by proper access controls and input validation - see the Flash Loans Attacks attack class for patterns
- Audit oracle price feeds for manipulation risks - ensure time-weighted average prices (TWAPs) or multi-source aggregators are used, not spot prices
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSecurity Audit History
- Audit Report 1 Report
Related Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Proof-of-Concept Exploits
On-Chain Evidence & References
- Twitter/X Alert https://twitter.com/peckshield/status/1647307128267476992
- Twitter/X Alert https://twitter.com/danielvf/status/1647329491788677121
- Twitter/X Alert https://twitter.com/hexagate_/status/1647334970258608131
- Reference https://blog.hundred.finance/15-04-23-hundred-finance-hack-post-…
Sources & References
Learn to Prevent the Next Hundred Finance
The Hundred Finance hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.