Nerve Finance Hack
Incident Overview
The attacker:
https://bscscan.com/address/0xd5476194…d69228
The transaction behind the attack:
https://bscscan.com/tx/0xea95925e…6fcf1d
The attacker:
- borrowed 50,000 BUSD using a flash loan from Fortube
- swapped 50,000 BUSD for 50,351 fUSDT from Ellipsis
- invoked the swap function of MetaSwap to swap 50,351 fUSDT for 36,959 Nerve 3-LP with a relatively big slippage
- invoked the removeLiquidityOneCoin() function of Nerve.3pool with the LP tokens (received in the previous step) to remove the liquidity of BUSD, i.e., 37,071 BUSD
- invoked the swapUnderlying() function of MetaSwap to swap BUSD for fUSDT, and received 51,494 fUSDT.
The attacker repeatedly executed the above steps to drain the liquidity of the MetaPool and finally harvested 900 BNB.
Stolen funds were deposited into Tornado Cash mixer:
https://bscscan.com/tx/0xcf43eefb…0aec90
https://bscscan.com/tx/0x55bd06a0…190a53
https://bscscan.com/tx/0x2dbc18c6…23067b
https://bscscan.com/tx/0x17cd04cb…334e7c
https://bscscan.com/tx/0xe5a0a058…4fa1f4
https://bscscan.com/tx/0x16ec28d4…896581
https://bscscan.com/tx/0x7f6b4313…0bb3c1
The rest were bridged though AnySwap:
https://bscscan.com/tx/0x0348cc92…2332a6
The swap function ignores the impact of the virtual price, which means the value of the LP token will be underestimated and more LP tokens could be swapped out. As a result, it is possible to harvest more pool stablecoins by first fetching back the liquidity of the underlying stablecoins with the corresponding LP token, and then swapping pool stablecoins by invoking the swapUnderlying() function.
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Nerve Finance, these are the critical security checks that could have prevented this incident (November 2021).
- Verify all logic paths related to Other are guarded by proper access controls and input validation
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialSecurity Audit History
- Audit Report 1 Report
Sources & References
Learn to Prevent the Next Nerve Finance
The Nerve Finance hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.