Merlin Labs Hack

TOTAL LOST $680K
Low Arithmetic Overflow & Underflow Attacks binance bsc

What happened

The attacker:

https://bscscan.com/address/0x400fa7ed…c162fa

The transaction behind the attack:

https://bscscan.com/tx/0x8e20a111…56ff97

The attacker:

- added a small sum of deposit to the LINK-BNB Vault at:

https://bscscan.com/tx/0x3ce0be64…f475ac

- sent 180 CAKE to the LINK-BNB Vault contract (leads to the hack)

- called getReward() with the deposit of LINK-BNB Vault from the first step

- with a large amount of CAKE token in the wallet balance of the vault contract (sent by the hacker in step 2), it returns a large amount of profit. As a result, the system minted 100 MERL as a reward to the hacker

- repeated 36 times, received 49K of MERL token in total

- swapped MERLIN token into 240 ETH and transferred out of BSC using Anyswap.

The attack was performed using a similar way as Bunny and Autoshark exploits.

Case & protocol details

Classification Other / Yield Aggregator / Protocol Logic / Ecosystem / Token & Share Accounting
Protocol Type Exploit/Other
Affected asset / contract MERL
Smart Contract Language Solidity
Official Website merlinlab.com/farm
Protocol Twitter/X @MerlinLab_

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.