Omm Finance Hack

TOTAL LOST $1.9M
Medium Other

What happened

On January 21 2023 Omm Protocol was exploited. The hacker withdrew about $1.9M in IUSDC, USDS, bnUSD, and sICX tokens.

On January 21 a hacker exploited a vulnerability in Omm by deploying a harmful contract. The hacker carried out 18 malicious transactions and was able to steal IUSDC, USDS, and bnUSD collateral that did not belong to them. They then used the stolen USDS as collateral to borrow sICX.

The bug was located in the Redeem function, which accepts an address as the collateral to be redeemed. The external call enabled the injection of a faulty smart contract, allowing the hacker to redeem the collateral without any prior deposit.

The hacker utilized Balanced to exchange the majority of the funds, which led to a significant deviation from the target price of 1 USD for bnUSD and other stablecoins.

They also moved IUSDC from ICON to other blockchains, such as Ethereum and Polygon, via Orbit Bridge.

Main exploit wallet:

hxc35cffe7c582cb313820fa6838dd357027ad3d07

Addresses on Ethereum and Polygon that received USDC via Orbit Bridge:

0x00082ff2…4cfd85

0x7e4d6232…efa60e

0x3b074b58…9e152a

0x49fedf6f…2eab55

0x517dfb86…dd22d6

0xA28408FD…eBa448

Case & protocol details

Classification Exchange (DEX)
Protocol Type Exploit/Other
Official Website omm.finance/
Protocol Twitter/X @ommfinance

Evidence & learning

Sources and on-chain records

Practice this exploit pattern safely

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.