MoonHacker Hack
What happened
On December 23, 2024, the MoonHacker vault contracts on Optimism were exploited for roughly $320,000 in USDC.
The attacker took out a flash loan in USDC from Aave and substituted a malicious contract for the mToken parameter in the MoonHacker vault’s executeOperation function. Because no validation prevented unauthorized addresses, the vault mistakenly granted approval to the attacker’s malicious contract. This facilitated a transfer of USDC from the vault, after which the attacker repeatedly called repayBorrow and redeem to siphon out remaining tokens.
They then repaid the flash loan, securing the stolen USDC in the process. MoonHacker deployers, who are unknown to Moonwell, are now working with relevant parties to investigate and recover the stolen funds. Importantly, no Moonwell core lending pools were compromised.
Exploit tx:
https://optimistic.etherscan.io/tx/0xd12016b2…54c4fe
Attacker address:
https://optimistic.etherscan.io/address/0x36491840…181f52
Case & protocol details
Evidence & learning
Attack pattern
Compare incidents →Sources and on-chain records
- report Report blog.solidityscan.com
- report Report binance.com
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.