MAAT Protocol Hack
What happened
On December 6, 2024, MEV bots drained about $239,973 from MAAT Protocol's internal Stargate USDT strategy on BNB Smart Chain. The protocol had not launched publicly yet. A share-accounting bug in the strategy's _withdraw function let a caller redeem 1 wei of shares without burning any shares, and an inflated price per share made that 1 wei worth a large part of the vault.
The first two attack transactions landed two blocks after MAAT's rebalancer redeposited 287,102 USDT into the strategy. MEV bots then replayed the attack in 61 more transactions. TenArmor spotted the drain and alerted MAAT through Stargate, and the team halted the system and pulled funds from all strategies.
MAAT says it reclaimed about $71.8K from attackers and BSC validators and covered the remaining ~$168K loss from its treasury. It postponed launch pending a strategy rewrite and multiple audits.
How it happened
- On November 30, 2024, MAAT withdrew 286,501 USDT from its Stargate BSC strategy. Because of a calculation error, not every share was burned, leaving 1 wei of shares outstanding.
- On December 5, a compound call added about 79 USDT of accumulated STG incentives to the strategy. With only 1 wei of shares in existence, the price per share (PPS) jumped.
_withdrawconverted assets to shares a second time (shares = convertToShares(assets)) before burning. For a 1 wei redemption at the inflated PPS, this made it possible to withdraw assets while burning zero shares.- On December 6, the rebalancer redeposited 287,102 USDT and received only 3,674 wei of shares, so each wei of shares now claimed a large amount of USDT.
- Two blocks later, a bot called
redeemwith 1 wei of shares repeatedly. Other MEV bots front-ran and copied it across 63 transactions in total, draining about $239,973.
Protocol details
Evidence
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.