Midas Capital Hack

TOTAL LOST $600K
Low Arithmetic Overflow & Underflow Attacks bsc

What happened

Midas Capital, a lending platform, was exploited resulting in a loss of over 600,000 $USD.

The Midas Capital, a borrowing and lending platform on the Binance Smart Chain, was exploited by a logic flaw in one of its contracts with unverified source code. As a result, the attacker was able to drain over 600,000 $USD worth of various tokens in stablecoins and $BNB. Part of the stolen amount was swapped for 510 $BNB and then transferred through TornadoCash.

The contract misused the redeem counter which, when provided with different amounts of HAY/BUSD AMM tokens, gave back multiple times the token value, behaving much like a free ATM.

Attacker Address:

https://bscscan.com/address/0x4b92cC34…470734

Malicious Transaction:

https://bscscan.com/tx/0x66654f11…ec2537

Funds Transfer Transaction:

https://bscscan.com/tx/0x4ab18c57…735383

Funds Transfer to TornadoCash Transaction:

https://bscscan.com/tx/0x50d2ac94…97edf1

Case & protocol details

Classification Protocol Logic / Borrowing and Lending / Token & Share Accounting
Protocol Type Lending
Smart Contract Language Solidity
Official Website www.midascapital.xyz/
Protocol Twitter/X @MidasCapitalxyz

Security review history

Evidence & learning

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.