Omm Finance Hack
What happened
On January 21 2023 Omm Protocol was exploited. The hacker withdrew about $1.9M in IUSDC, USDS, bnUSD, and sICX tokens.
On January 21 a hacker exploited a vulnerability in Omm by deploying a harmful contract. The hacker carried out 18 malicious transactions and was able to steal IUSDC, USDS, and bnUSD collateral that did not belong to them. They then used the stolen USDS as collateral to borrow sICX.
The bug was located in the Redeem function, which accepts an address as the collateral to be redeemed. The external call enabled the injection of a faulty smart contract, allowing the hacker to redeem the collateral without any prior deposit.
The hacker utilized Balanced to exchange the majority of the funds, which led to a significant deviation from the target price of 1 USD for bnUSD and other stablecoins.
They also moved IUSDC from ICON to other blockchains, such as Ethereum and Polygon, via Orbit Bridge.
Main exploit wallet:
hxc35cffe7c582cb313820fa6838dd357027ad3d07
Addresses on Ethereum and Polygon that received USDC via Orbit Bridge:
Case & protocol details
Evidence & learning
Sources and on-chain records
- report Report twitter.com
- report Report forum.omm.finance
- analysis Web Archive archive.ph
Practice this exploit pattern safely
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.