Midas Capital Hack

REPORTED LOSS $660K
Low Flashloan Reentrancy Attack polygon

What happened

Midas Capital's Jarvis lending pool accepted WMATIC-stMATIC Curve LP tokens as collateral. A read-only reentrancy exposed a temporarily inflated collateral price during Curve liquidity removal, letting the attacker borrow more assets than the position should support.

Technical Root Cause

Midas consumed Curve's get_virtual_price during an intermediate withdrawal state. The LP supply had decreased while the invariant calculation still reflected stale state, overstating collateral and permitting excessive borrowing.

Case & protocol details

Classification Ecosystem / Borrowing and Lending / Reentrancy
Protocol Type Lending
Implementation language Solidity
Official Website app.midascapital.xyz/
Protocol Twitter/X @MidasCapitalxyz

How it happened

  1. The attacker used flash-loaned liquidity to obtain Curve LP collateral and establish a large liquidity position.
  2. During liquidity removal, Curve burned LP tokens before completing the state update used for virtual-price calculation.
  3. A callback let the attacker borrow from Midas while its oracle read the inflated intermediate price.
  4. Midas approved excessive loans against the overstated collateral.

Security review history

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.