MintRisesPrices Hack

Reported loss $59K
BNB Chain
Reentrancy

What happened

On 2 July 2024, MintRisesPrices (MRP) on BNB Chain lost about $59,000 to a reentrancy attack, according to SlowMist. The vulnerable contract was WMRP (0x35f5...af7d), a wrapped-MRP contract that held BNB and made external calls while processing a transfer.

Verichains found that a zero-value transfer of WMRP to oneself sent the contract into its _removeLiquidity branch. That branch called back into the attacker's contract before WMRP had finished updating its accounting. From that callback, the attacker sent BNB back into WMRP's receive() function. Repeating this let them take more MRP than they were entitled to and drain the BNB held by the contract. Verichains measured about 17 BNB drained in the transaction it analysed (0x4353a6d3...393101, attacker 0x132d...b138).

How it happened

  1. The attacker transferred 0 WMRP to their own address. In WMRP's transfer logic, this special case triggers the _removeLiquidity path.
  2. During liquidity removal, WMRP made an external call to the attacker's contract before its internal state was final.
  3. Inside that callback, the attacker re-entered WMRP by sending BNB back to the contract's receive() function. receive() ran against the stale state.
  4. By repeating the cycle, the attacker obtained more MRP than allowed and drained the BNB balance of the WMRP contract.

Protocol details

Classification Reentrancy
Protocol Type DeFi Protocol
Implementation language Solidity

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.