Mirror Protocol Hack

TOTAL LOST $90.0M
High #84 All-Time Other

Summarize with AI

Affected Chain 2021 Incident surface
Recovered - No recovery reported
All-Time Rank #84 By amount stolen
Protocol Type Dexs Target category

Incident Overview

Terra's Mirror Protocol was exploited for ~$90 million by a hacker. The attack went unnoticed for 7 months before a Terra community member called FatManTerra identified the exploit.

The Mirror Protocol was a synthetic assets protocol that allowed users to deposit USTC or LUNAC with a lockup period in order to mint synthetic stocks and commodities. The protocol allowed user to utilize both short and long strategies. The shorting functionality could only be accessed by locking funds for 14 days. The lock contract would then generate a position ID which was used in order to release the users funds if desired.

The attacker initially deposited 100,000 UST to the lock contract in this transaction:

https://finder.terra.money/classic/tx/29C9CFBBC9562100A5DB19D705E440CE24768D3BDE399507FA1C2EC2424413C4 in order to prepare the attack.

The attacker noticed that the lock contract had a vulnerability which allowed the attacker to unlock funds by using the same position ID over and over again as can be seen in this transaction: https://finder.terra.money/classic/tx/08DD2B70F6C2335D966342C20C1E495FD7A8872310B80BAF3450B942F79EBC1F, exploiting the protocol for approx. $90 million USTC in the process.

Attacker address: https://finder.terra.money/mainnet/address/terra1200zm8crgjaj949ta8r7p6pay0qq638js4sdmh

Incident Report

Protocol / Project Mirror Protocol
Date of Incident
Attack Technique Other
Classification Other,Borrowing and Lending
Primary Source View Post-Mortem

Protocol Information

Protocol Type Dexs
Affected Token MIR
Official Website terra.mirror.finance/
Protocol Twitter/X @mirror_protocol
Team Public / Doxxed
Source Code Unverified

Market Context at Time of Hack

Token Categories
Cosmos Ecosystem DeFi Derivatives Ethereum Ecosystem Synthetics Arrington XRP Capital Portfolio Pantera Capital Portfolio Terra Ecosystem

What the Attacker Needed to Succeed

Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.

Technical Knowledge Deep understanding of other and Solidity and EVM internals
Capital Required Seed capital to cover gas and initial position setup
On-Chain Access Ability to interact with smart contracts and deploy a custom exploit contract
Protocol Analysis Identification of the exploitable vulnerability in Mirror Protocol's contract logic - root cause: other,borrowing and lending
Execution Speed Precise transaction ordering and timing to exploit the vulnerability within a single atomic block
Obfuscation Plan A strategy to launder and move stolen funds - typically through mixers, cross-chain bridges, or decentralized DEX swaps to resist tracing

What Auditors Should Check

Could this have been caught in audit? Likely — with a thorough Other audit checklist and test coverage

If you're auditing a protocol with similar architecture to Mirror Protocol, these are the critical security checks that could have prevented this incident (October 2021).

  • Verify all logic paths related to Other are guarded by proper access controls and input validation
  • Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs

Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.

Free Trial

Sources & References

Learn to Prevent the Next Mirror Protocol

The Mirror Protocol hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.

Recreate exploit patterns safely Free Trial