NORMIE Hack

Reported loss $882K
Base
Unknown

What happened

On 26 May 2024 an attacker exploited a logic flaw in the NORMIE memecoin contract on Base and extracted about 224.98 ETH (about $881,686, per CertiK). The token's premarket-user logic added any address that received exactly the deployer's token balance as a premarket_user. That status made the contract mint tokens to itself, which in turn fired its swapAndLiquify routine repeatedly. The attacker used this to inflate NORMIE's supply from the intended 1 billion to over 650 billion tokens. NORMIE's price fell about 99% within minutes, and its market cap dropped from about $41 million to almost nothing.

The attacker then offered to return 90% of the stolen funds, about 200 ETH, if the team added 600 ETH from its developer wallet and launched a new token to compensate holders. The team said it accepted. The main exploit transaction was 0xa618933a0e0ffd0b9f4f0835cc94e523d0941032821692c01aa96cd6f80fc3fd, from attacker wallet 0xf7f3a556Ac21d081F6dBa961B6A84E52e37A717D.

How it happened

  1. The attacker bought NORMIE in an amount equal to the deployer's balance. Receiving exactly that amount made their address a premarket_user.
  2. They flash-borrowed about 11.3M NORMIE and sold about 9M of it for 65.97 WETH on the SushiSwap pair.
  3. They repeatedly transferred about 2.27M NORMIE to the pair and called skim() to take it back. Each round made the contract mint tokens to itself and cross the thresholds that trigger swapAndLiquify.
  4. The runaway minting pushed NORMIE's price down, so the attacker bought back about 11M NORMIE for about 0.5 WETH and repaid the flash loan, keeping the ETH.

Protocol details

Classification Protocol Logic
Protocol Type Token
Implementation language Solidity
Protocol links Website @NormieBase

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.