Mad Meerkat Finance Hack
What happened
On May 4, 2022, the front-end of the MM Finance protocol was hacked, which allowed the hacker to change the router address and redirect all the funds of users who somehow interacted with the protocol through the front-end to their wallet.
The exploit lasted approximately three hours, then the team turned off the front-end.
Team members advised users on Discord not to interact with the site.
Attacker address: https://cronoscan.com/address/0xb3065fe2…db9a6b
Attacker fundings address: https://cronoscan.com/address/0x3fbaf5ee…eee7e3. Then they were mapped to: https://crypto.org/explorer/account/cro1ukvuw3qzjtt8wg5hsze4f2c3c8xqvtwgcnxah2. Actual fundings transaction: https://crypto.org/explorer/tx/0C7193F9E2D8FAE789A4B21DBC554D942329A5DA8734541563F339867740527B. This fundings were mapped the 0x address to the underlying address: https://crypto-org-chain.github.io/cronos-address-webtool/
600+ transactions were redirected, and the profits were exchanged for USDT and transferred through the bridge back to ETH before being deposited (743 ETH so far) in Tornado Cash.
Total number of losses: $2M
Case & protocol details
Security review history
Evidence & learning
Sources and on-chain records
- report Report twitter.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.