MooCakeCTX Hack
Incident Overview
MooCakeCTX was exploited via a flash loan attack. The attacker's profit reached 122,960 $USD.
MooCakeCTX is a yield protocol on the Binance Chain. The protocol supports $CAKE deposits for $mooCakeCTX. The attacker took 400,000 $BUSD as a flash loan and exploited the protocol's smart contract for 424 $BNB.
The attacker's malicious smart contract bypassed isContract() function check by performing actions on the constructor and got rewards as $mooCakeCTX tokens after depositing $CAKE tokens. The flash loan was paid back after repeating previous actions multiple times and the exploiter took a profit of 424 $BNB. All the stolen funds were transferred to several EOA addresses in 4 transactions.
Attacker address:
https://bscscan.com/address/0x35700c4a…0facd5
Malicious contract:
https://bscscan.com/address/0x71ac864f…10467c
Malicious transaction:
https://bscscan.com/tx/0x03d36346…d2ec8e
Funds transfer transactions:
https://bscscan.com/tx/0x963d1ff2…9cad6a
https://bscscan.com/tx/0x602c2220…87ba45
https://bscscan.com/tx/0x44922e96…9ec913
https://bscscan.com/tx/0x58096e41…cca119
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to MooCakeCTX, these are the critical security checks that could have prevented this incident (November 2022).
- Verify all logic paths related to Flash Loan Attack are guarded by proper access controls and input validation - see the Flash Loans Attacks attack class for patterns
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialRelated Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Sources & References
Learn to Prevent the Next MooCakeCTX
The MooCakeCTX hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.