Midas Capital Hack

TOTAL LOST $660K
Low Flash Loan Attacks polygon

What happened

Midas Capital protocol was exploited via a flashloan attack. The attacker stole worth around $650k USD.

Midas Capital protocol smart contract was exploited using multiple patterns such as flashloan, reentrancy, and code logic issues. Flashloan, taken, from the balancerV2 pool was used to perform an attack on the Midas pool. The logic of calculation of a position's collateral was exploited and gave an opportunity to the attacker to gain about  660k MATIC of profit.

After that MATIC tokens were transferred to multiple addresses on Polygon network.

Exploit TX:

https://polygonscan.com/tx/0x00534902…0a2c2f

Exploiter addresses:

https://polygonscan.com/address/0x1863b747…d08611

https://polygonscan.com/address/0xe53955d2…e359be

https://polygonscan.com/address/0x123bb33d…293eb8

https://polygonscan.com/address/0x7d27bc40…1d6c40

https://polygonscan.com/address/0xb6ac8cbd…33f429

https://polygonscan.com/address/0x49605afe…8e049c

https://polygonscan.com/address/0x8dded7da…c344ac

https://polygonscan.com/address/0x5ad4238b…d14a0d

https://polygonscan.com/address/0x65281cad…5a72ec

https://polygonscan.com/address/0x7de62e82…7f5922

https://polygonscan.com/address/0x62cc8544…957a8e

https://polygonscan.com/address/0x1395d3d5…8317ff

Case & protocol details

Classification Ecosystem / Borrowing and Lending / Reentrancy
Protocol Type Lending
Smart Contract Language Solidity
Official Website app.midascapital.xyz/
Protocol Twitter/X @MidasCapitalxyz

Security review history

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.