Midas Capital Hack
What happened
Midas Capital, a lending platform, was exploited resulting in a loss of over 600,000 $USD.
The Midas Capital, a borrowing and lending platform on the Binance Smart Chain, was exploited by a logic flaw in one of its contracts with unverified source code. As a result, the attacker was able to drain over 600,000 $USD worth of various tokens in stablecoins and $BNB. Part of the stolen amount was swapped for 510 $BNB and then transferred through TornadoCash.
The contract misused the redeem counter which, when provided with different amounts of HAY/BUSD AMM tokens, gave back multiple times the token value, behaving much like a free ATM.
Attacker Address:
https://bscscan.com/address/0x4b92cC34…470734
Malicious Transaction:
https://bscscan.com/tx/0x66654f11…ec2537
Funds Transfer Transaction:
https://bscscan.com/tx/0x4ab18c57…735383
Funds Transfer to TornadoCash Transaction:
https://bscscan.com/tx/0x50d2ac94…97edf1
Case & protocol details
Security review history
- Zellic Report
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report twitter.com
- analysis Website reference twitter.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.