Mosca Hack
What happened
On January 8, 2025, the Mosca smart contract on Binance Smart Chain was exploited due to flawed balance resets in the exitProgram function. The attacker took advantage of improperly cleared user balances, repeatedly withdrawing tokens and resulting in a total loss of about $19,500.
The vulnerability stemmed from the withdrawAll function, which calculates a user’s withdrawal amount by summing user.balance, user.balanceUSDT, and user.balanceUSDC. After the withdrawal, only user.balance was set to zero, leaving user.balanceUSDT and user.balanceUSDC intact. An attacker increased their balance in USDC, joined the contract’s reward queue, and then repeatedly invoked exitProgram to withdraw tokens multiple times.
Each call exploited the non-zero USDT/USDC balances that were never reset, ultimately allowing the attacker to accumulate roughly $19,500 in stolen funds.
Protocol details
Evidence
- report Report blog.solidityscan.com
- analysis DeFiLlama defillama.com
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.