MoonHacker Hack

TOTAL LOST $320K
Low Flash Loan Attacks

What happened

On December 23, 2024, the MoonHacker vault contracts on Optimism were exploited for roughly $320,000 in USDC.

The attacker took out a flash loan in USDC from Aave and substituted a malicious contract for the mToken parameter in the MoonHacker vault’s executeOperation function. Because no validation prevented unauthorized addresses, the vault mistakenly granted approval to the attacker’s malicious contract. This facilitated a transfer of USDC from the vault, after which the attacker repeatedly called repayBorrow and redeem to siphon out remaining tokens.

They then repaid the flash loan, securing the stolen USDC in the process. MoonHacker deployers, who are unknown to Moonwell, are now working with relevant parties to investigate and recover the stolen funds. Importantly, no Moonwell core lending pools were compromised.

Exploit tx:

https://optimistic.etherscan.io/tx/0xd12016b2…54c4fe

Attacker address:

https://optimistic.etherscan.io/address/0x36491840…181f52

Case & protocol details

Classification Yield Aggregator
Protocol Type Exploit/Flash Loan Attack

Evidence & learning

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.