Maiar DEX Hack

TOTAL LOST $113M
Critical #75 All-Time Other

Summarize with AI

Affected Chain 2022 Incident surface
Recovered $113.0M 100.0% returned
All-Time Rank #75 By amount stolen
Protocol Type Exploit/Other Target category

Incident Overview

Maiar DEX was the victim of an attack by hackers who found and exploited a vulnerability in order to empty the reserves of the protocol. Due to this vulnerability, when a $WEGLD contract called a Maiar contract, it allowed Maiar to perform a token transfer in the context of the $WEGLD contract, the calling party. Maiar DEX was successfully recovered by the Elrond team, and user funds were not affected

The Maiar DEX protocol was attacked by hackers who took advantage of a vulnerability in the WEGLD contract to steal funds from the protocol on the Elrond network. The attacker's accounts were created almost simultaneously and tokens in the amount of 1.959 $EGLD were sent to each of them from Binance Hot Wallet:

1) https://explorer.elrond.com/transactions/ba7bcea55911973556c0c855a912c868e76a658792b62a6688c16a14c98a0102

2) https://explorer.elrond.com/transactions/27935d8bceaee5b179bddb1dcd9683a3c227055c8ac70b4bd5f3a40a2b5f6dd1

3) https://explorer.elrond.com/transactions/73f39d3edf0cf5f0893fa3a8175f614329960572e2843f6a21f60b5e1bf778f5

After the accounts were created and smart contracts as well, they called the withdraw() function and received a total of 1,650,000 $EGLD. The most important here is the wrat_egls_callback() function. This function enables the wrapping and unwrapping of the $EGLD token.

In the transaction below, it can be noticed that as the new smart contract sends a small amount of $EGLD to the wrapEgId() method and this method sends $WEDLD to the wrap_edId_callback() method of the new contract:

https://explorer.elrond.com/transactions/848b5a96bd95d3537f2bb8cfc5c1ebc5ec580e72214dd75c85be718ae0bbf3fb#4159433916247dbdbfbbf31d8a4cc8ce14a3a86e5a5f7beb1cddcf5abc59b83e

Deploying the wrap_egId_callback() method, was found a call of the managedExecuteOnDestContextByCaller() method, which allows attacker to "ask" the victim's contract to send funds to any other address that the attacker indicates, which happened during the attack on Maiar DEX. The Elrond team paused the work of Maiar DEX, they also froze stablecoins so that the hacker would not be able to withdraw funds through the bridge to another network. Having connections with other major exchanges, they handed over a blacklist with addresses so that the fraudster would not be able to withdraw funds. The executeOnDestContextByCaller() function was removed to avoid a repeat attack. Then the team began to restore the liquidity pool by returning all funds and restoring the price of the token, based on the price indicated by Binance.

Attacker addresses:

1) https://explorer.elrond.com/accounts/erd1cura2qq8skel5fsxrpxyysjkaw6durengtkencrezkw78y6y2zhscf854j

2) https://explorer.elrond.com/accounts/erd1yrf9qeuqkcjeh5c4xn628mags7cse4r9ra2p2ggmlgfqq3l3v6pqxfu950

3) https://explorer.elrond.com/accounts/erd16syfkds2faezhqa7pn5n8fyjkst70l5qefpmc0r960467snlgycq4ww0rt

Contract addresses:

1) https://explorer.elrond.com/accounts/erd1qqqqqqqqqqqqqpgq85hhnppjcdamledp3usgkm3lm832jekw2zhsajjztn

2) https://explorer.elrond.com/accounts/erd1qqqqqqqqqqqqqpgqqucnpav4dguh4zf6nvd48l68k2nxhyu0v6pqqntgfs

3) https://explorer.elrond.com/accounts/erd1qqqqqqqqqqqqqpgqll7yerx6v67p0s8va0h09dgv7x30nlergycqt2qzmp

Contract deployment transaction by the attacker address (erd1...854j): https://explorer.elrond.com/transactions/9404479926078441d8fd8844ec4787c4c35c554628abdc7605c8084f49299352

Contract deployment transaction by the attacker address (erd1...u950): https://explorer.elrond.com/transactions/39c7aebfe5ebbe4bcc285ef5cc99869486705afa4ce94071c5aafc6124864fb7

Contract deployment transaction by the attacker address (erd1...ww0rt): https://explorer.elrond.com/accounts/erd1qqqqqqqqqqqqqpgqll7yerx6v67p0s8va0h09dgv7x30nlergycqt2qzmp

Transactions of theft of funds from the Maiar DEX:

400k EGLD: https://explorer.elrond.com/transactions/8b8c332577e5b8bdd4e13450ea92b7c6b0ca15399f1f0bb38fc215cfc3ddb490

450k EGLD: https://explorer.elrond.com/transactions/39998ab5c929fa67e95d0c64081697fc4207235dbfeaaff10fb2704a6c7716b6

800k EGLD: https://explorer.elrond.com/transactions/41effd8536376f3a2edba7074c02776edae94bb5b464485ac414847202eebbe2

Recovered funds were send to one of Elrond addresses: https://explorer.elrond.com/accounts/erd1pml9k2tsqsnvtmmalglt2su0sn3cguvr8e8jq0gy69zw2ldcej2qapml9a

Incident Report

Protocol / Project Maiar DEX
Date of Incident
Attack Technique Other
Classification Exchange (DEX)

Protocol Information

Protocol Type Exploit/Other
Affected Token MEX
Official Website maiar.exchange/
Protocol Twitter/X @getMaiar
Team Public / Doxxed
Source Code Verified On-Chain

Market Context at Time of Hack

Token Categories
Decentralized Exchange (DEX) Token DeFi Ethereum Ecosystem Solana Ecosystem Polygon Ecosystem Arbitrum Ecosystem BNB Chain Ecosystem Base Ecosystem

What the Attacker Needed to Succeed

Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.

Technical Knowledge Deep understanding of other and Solidity and EVM internals
Capital Required Seed capital to cover gas and initial position setup
On-Chain Access Ability to interact with smart contracts and deploy a custom exploit contract
Protocol Analysis Identification of the exploitable vulnerability in Maiar DEX's contract logic - root cause: exchange (dex)
Execution Speed Precise transaction ordering and timing to exploit the vulnerability within a single atomic block
Obfuscation Plan A strategy to launder and move stolen funds - typically through mixers, cross-chain bridges, or decentralized DEX swaps to resist tracing

What Auditors Should Check

Could this have been caught in audit? Likely — with a thorough Other audit checklist and test coverage

If you're auditing a protocol with similar architecture to Maiar DEX, these are the critical security checks that could have prevented this incident (June 2022).

  • Verify all logic paths related to Other are guarded by proper access controls and input validation
  • Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs

Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.

Free Trial

Funds Recovery

100.0%

Recovered

$113.0M

Net Loss

0

Sources & References

Learn to Prevent the Next Maiar DEX

The Maiar DEX hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.

Recreate exploit patterns safely Free Trial