Indexed Finance Hack
Incident Overview
The DEFI5 and CC10 index tokens were exploited using flash loans, resulting in a loss of approximately $156 million.
The attacker targeted the DEFI5 and CC10 index tokens using flash loans of other assets in the pool to buy out UNI, which decreased the extrapolated value due to the delay in updating UNI’s weight decrease. The pool was valued at 29,851 SUSHI ($300k) after executing the updateMinimumBalance function with the gamed pool value. The attacker then deposited small amounts of SUSHI into the pool, resulting in a massively inflated amount of DEFI5 tokens.
Approximately $156m worth of flash swaps in UNI, AAVE, COMP, CRV, MKR, SNX were used for dumping tokens in the pool, minting new DEFI5 tokens, and then burning the DEFI5 for all of the underlying assets. The same scenario was used for the CC10 index pool.
The attacker's address:
https://etherscan.io/address/0xba5ed148…a22ebe
The exploiter contract:
https://etherscan.io/address/0xfbc2e6b1…67464a
The attack targeted the DEFI5 index token at:
https://etherscan.io/tx/0x44aad3b8…cd95aa
and CC10 index token at:
https://etherscan.io/tx/0xbde4521c…ca4417
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Indexed Finance, these are the critical security checks that could have prevented this incident (October 2021).
- Verify all logic paths related to Flashloan Price Oracle Attack / Other are guarded by proper access controls and input validation - see the Flash Loans Attacks attack class for patterns
- Audit oracle price feeds for manipulation risks - ensure time-weighted average prices (TWAPs) or multi-source aggregators are used, not spot prices
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSecurity Audit History
- Audit Report 1 Report
Related Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Proof-of-Concept Exploits
On-Chain Evidence & References
Sources & References
- 01
-
02
Reference https://rekt.news/indexed-finance-rekt/
Learn to Prevent the Next Indexed Finance
The Indexed Finance hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.