LAURA Hack
What happened
On Jan 8, 2025, the LAURA token contract was exploited for around $48,000 due to a flawed removeLiquidityWhenKIncreases function.
The hacker first swapped significant WETH for LAURA and contributed LAURA and WETH liquidity to the Uniswap pool, raising the constant product (x * y = k). They then invoked the contract’s removeLiquidityWhenKIncreases() function, which failed to correctly handle the heightened K and thus allowed the attacker to remove more tokens than they deposited. Finally, the attacker traded back into WETH once the pool was misaligned, walking away with a net profit of approximately $48,000.
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report x.com
- report Report nickfranklin.site
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.