MintRisesPrices Hack
What happened
On 2 July 2024, MintRisesPrices (MRP) on BNB Chain lost about $59,000 to a reentrancy attack, according to SlowMist. The vulnerable contract was WMRP (0x35f5...af7d), a wrapped-MRP contract that held BNB and made external calls while processing a transfer.
Verichains found that a zero-value transfer of WMRP to oneself sent the contract into its _removeLiquidity branch. That branch called back into the attacker's contract before WMRP had finished updating its accounting. From that callback, the attacker sent BNB back into WMRP's receive() function. Repeating this let them take more MRP than they were entitled to and drain the BNB held by the contract. Verichains measured about 17 BNB drained in the transaction it analysed (0x4353a6d3...393101, attacker 0x132d...b138).
How it happened
- The attacker transferred 0 WMRP to their own address. In WMRP's transfer logic, this special case triggers the
_removeLiquiditypath. - During liquidity removal, WMRP made an external call to the attacker's contract before its internal state was final.
- Inside that callback, the attacker re-entered WMRP by sending BNB back to the contract's
receive()function.receive()ran against the stale state. - By repeating the cycle, the attacker obtained more MRP than allowed and drained the BNB balance of the WMRP contract.
Protocol details
Evidence
- report SlowMist Security Alert on $MRP @MintRisesPrices (X, via fxtwitter mirror) x.com
- code pcaversaccio/reentrancy-attacks README (Mint Raises Prices attack entry) github.com
- analysis DeFiLlama defillama.com
- analysis MRP token exploit analysis (Verichains) blog.verichains.io
- analysis SlowMist Hacked, BSC category (2024-07-02 MintRisesPrices entry) hacked.slowmist.io
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.