MicDao Hack
What happened
On October 18, 2023 an attacker used a flash loan to drain about 12,260 BUSDT from the MicDao/BUSDT pool on PancakeSwap (BNB Chain). CertiK reported a gain of $12,263 and ChainAegis a loss of about $13,000.
MicDao was being sold through a sale contract that handed out a fixed 10 MicDao per 1 BUSDT and never checked the live pool price. The attacker first bought up almost all the MicDao in the thin pool, pushing its pool price far above the sale rate. It then bought 1.6 million MicDao cheaply from the sale contract and sold them into the pool. The token burns 45% of every sale into the pair, but the pool price had been pushed so high that the dump still returned more BUSDT than the flash loan had cost.
Attacker: 0xcd03ed98868a6cd78096f116a4b56a5f2c67757d
Attack contract: 0x502b4a51ca7900f391d474268c907b110a277d6f
Attack tx: 0x24a2fbb27d433d91372525954f0d7d1af7509547b9ada29cc6c078e732c6d075
How it happened
- The attack contract flash-borrowed about 670,900 BUSDT from a DODO
DPPOraclepool. - It swapped 500,000 BUSDT for MicDao in the PancakeSwap pair, cutting the pool's MicDao reserve from about 177,869 to about 6,133 and raising the pool price from about 0.10 to about 84 BUSDT per MicDao.
- It deployed 80 helper contracts. Each sent 2,000 BUSDT to the sale contract's
swapfunction and received a fixed 20,000 MicDao, for 1.6 million MicDao in total for 160,000 BUSDT. - It sold all of its MicDao (about 1.77 million) back into the pair. 45% was burned on transfer, but the rest still returned about 672,260 BUSDT.
- It repaid the flash loan and kept about 12,260 BUSDT.
Protocol details
Evidence
- report CertiK Skynet alert: flashloan exploit on MicDao, attacker gained $12,263 twitter.com
- report ChainAegis alert: MicDao flash loan attack, ~$13,000 loss twitter.com
- analysis DeFiLlama defillama.com
- analysis DeFiHackLabs MicDao_exp.sol raw.githubusercontent.com
- analysis MicDao exploit analysis (Crypto Training) crypto.training
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.