MOBOX Hack

Reported loss $750K
Optimism
Borrow Logic Flaw

What happened

On March 14, 2024, attackers drained about $750,000 in USDT from a lending protocol called MOBOX on Optimism, according to SlowMist. Users posted MO tokens as collateral to borrow USDT. The attacker called its borrow() function over and over, pushing up the MO price the contract used and collecting referral rewards through a referrer address they also controlled, until a small amount of MO could borrow a large amount of USDT.

The attack transaction was 0x4ec3061724ca9f0b8d400866dd83b92647ad8c943a1c0ae9ae6c9bd1ef789417, from attacker addresses 0x4e2c6096985e0b2825d06c16f1c8cdc559c1d6f8 and 0x96f004c81d2c7b907f92c45922d38ab870a53945 (the referrer). The DeFiHackLabs reproduction puts the profit at about $413,000, so the two figures should be read as estimates.

How it happened

  1. The attacker bound a referrer address they controlled (0x96f0...3945) to their borrowing account.
  2. Each borrow() call burned part of the MO tokens in the pool. The contract priced MO from that pool, so every burn raised the MO price and increased how much USDT the same MO could borrow.
  3. Each borrow() also paid a referral reward to the referrer, sized by the amount of MO supplied. The attacker moved that reward straight back to the attack contract to make the next loan bigger.
  4. The attacker looped borrow, redeem() and reward recycling many times in one transaction, inflating the MO price further each round.
  5. With MO heavily overpriced, a small amount of MO borrowed a large amount of USDT, and the attacker swapped out of the now unbalanced pool for profit.

Protocol details

Classification Protocol Logic
Protocol Type Gaming
Implementation language Solidity
Protocol links Website @MOBOX_Official

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.