Hunny Finance Hack

Reported loss Not disclosed
BNB Chain
Incorrect Share Accounting

What happened

Hunny Finance runs PancakeHunny, a yield optimizer on BNB Chain built on top of PancakeSwap. On 3 June 2021, two days after HUNNY listed on PancakeSwap, an attacker tricked its HUNNY Minter into minting far more reward tokens than it should have, then sold them on PancakeSwap.

The team says the attack ran from about 02:12 to 02:42 UTC across 100 transactions and earned the attacker 216 BNB (WatchPug reported 38.9 ETH taken out after the proceeds were converted to ETH). The exploiter's wallet was 0x0ef50be29c82ecf2158ec1886dc6692a2b0db411. User deposits in the Hives (vaults) were not taken. The damage was the extra HUNNY that was minted and sold, which pushed the token price down. The team stopped the Minter at 02:42 UTC and changed it to mint only against profits actually received from vaults. It sent the new code to CertiK for audit and said it would use fees to buy back and burn HUNNY.

How it happened

  1. The attacker swapped WBNB for CAKE on PancakeSwap and staked in PancakeHunny's CAKE-BNB Hive.
  2. They then sent CAKE directly to the HUNNY Minter contract.
  3. When the Hive paid performance fees, mintFor() converted the Minter's entire token balance (balanceOf(address(this))) into HUNNY-BNB LP instead of just the fee it had received. That inflated LP amount was used as the profit figure for minting HUNNY.
  4. Because the donated CAKE counted as profit, the Minter minted excess HUNNY. The attacker collected it by unstaking from the Hive.
  5. The attacker sold the HUNNY on PancakeSwap and repeated the cycle, then converted the remaining WBNB to ETH and moved it out.

Protocol details

Classification Token & Share Accounting
Protocol Type Yield
Implementation language Solidity
Protocol links Website @HunnyFinance

Security review history

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.