Midas Capital Hack
What happened
Midas Capital's Jarvis lending pool accepted WMATIC-stMATIC Curve LP tokens as collateral. A read-only reentrancy exposed a temporarily inflated collateral price during Curve liquidity removal, letting the attacker borrow more assets than the position should support.
Midas consumed Curve's get_virtual_price during an intermediate withdrawal state. The LP supply had decreased while the invariant calculation still reflected stale state, overstating collateral and permitting excessive borrowing.
Case & protocol details
How it happened
- The attacker used flash-loaned liquidity to obtain Curve LP collateral and establish a large liquidity position.
- During liquidity removal, Curve burned LP tokens before completing the state update used for virtual-price calculation.
- A callback let the attacker borrow from Midas while its oracle read the inflated intermediate price.
- Midas approved excessive loans against the overstated collateral.
Security review history
- Zellic Report
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Post-mortem rekt.news
- report Midas Capital - REKT rekt.news
- analysis Website reference twitter.com
- analysis Website reference twitter.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.