Merlin Labs Hack
What happened
The attacker:
https://bscscan.com/address/0x400fa7ed…c162fa
The transaction behind the attack:
https://bscscan.com/tx/0x8e20a111…56ff97
The attacker:
- added a small sum of deposit to the LINK-BNB Vault at:
https://bscscan.com/tx/0x3ce0be64…f475ac
- sent 180 CAKE to the LINK-BNB Vault contract (leads to the hack)
- called getReward() with the deposit of LINK-BNB Vault from the first step
- with a large amount of CAKE token in the wallet balance of the vault contract (sent by the hacker in step 2), it returns a large amount of profit. As a result, the system minted 100 MERL as a reward to the hacker
- repeated 36 times, received 49K of MERL token in total
- swapped MERLIN token into 240 ETH and transferred out of BSC using Anyswap.
The attack was performed using a similar way as Bunny and Autoshark exploits.
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Post-mortem rekt.news
- report Post-mortem rekt.news
- analysis Website reference watchpug.medium.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.