Origin Protocol Hack
Incident Overview
Origin Dollar (OUSD) was exploited due to a reentrancy attack, leading to an excess minting of OUSD and a loss of 70,000 ETH.
The attacker borrowed 70,000 ETH from dYdX and exchanged a portion of it for USDT and DAI on Uniswap. They then used these stablecoins to mint OUSD from the Origin Protocol's vault. The attacker exploited a reentrancy vulnerability in the mint function of the OUSD contract to mint more OUSD than the equivalent stablecoin collateral in the vault.
This resulted in the attacker holding more OUSD than the total value in the vault. The attacker then exchanged the excess OUSD for USDT and DAI on Uniswap and SushiSwap, and withdrew the remaining stablecoins from the OUSD vault. Finally, the attacker returned the borrowed ETH to dYdX and transferred the stolen funds to their account.
The attacker's address:
https://etherscan.io/address/0xb77f7bbaβ¦079f83
The transaction behind the attack:
https://etherscan.io/tx/0xe1c76241β¦2a8401
The contract deployed at:
https://www.contract-library.com/contracts/Ethereum/0x47c3d843β¦0fdfe2
- 1,000,000 DAI was transferred to the attackerβs account
https://etherscan.io/tx/0x8c0459b6β¦84cd95
- 1,138,449.12 OUSD was redeemed for a mix of stablecoins
https://etherscan.io/tx/0xae6bee28β¦83f6bb
- 531,688.76 OUSD was redeemed for a mix of stablecoins
https://etherscan.io/tx/0xa990fe2cβ¦26538f
- 248,059.48 OUSD was redeemed for a mix of stablecoins
https://etherscan.io/tx/0xe95b4d3dβ¦c14e55
- 543,305.34 USDT and 226,832.53 USDC were converted to ETH on Uniswap and transferred to the attackerβs account along with 1,128,244.36 DAI
https://etherscan.io/tx/0x49d59b45β¦f33aec
- 115,732.21 OUSD was redeemed for a mix of stablecoins
https://etherscan.io/tx/0xcff80dddβ¦c089b4
- 53,994.89 OUSD was redeemed for a mix of stablecoins
https://etherscan.io/tx/0x47e515d5β¦847343
- 300,000.00 OUSD was exchanged for 60,505.30 USDT on Uniswap
1,000,000.00 OUSD was exchanged for 187,152.67 USDT on SushiSwap
https://etherscan.io/tx/0x8a1907dbβ¦d76b15
- 25,191.33 OUSD was redeemed for a mix of stablecoins
https://etherscan.io/tx/0xf14f4158β¦3633d9
- 300,000.00 OUSD was exchanged for 29,803.08 USDT on Uniswap
1,000,000.00 OUSD was exchanged for 98,401.29 USDT on SushiSwap
https://etherscan.io/tx/0x8eba96d3β¦3a29e7
- 11,616.27 OUSD was redeemed for a mix of stablecoins
https://etherscan.io/tx/0x9a133457β¦af0383
- 434,407.95 USDT and 24,443.08 USDC were converted to ETH on Uniswap and transferred to the attackerβs account along with 121,577.54 DAI
https://etherscan.io/tx/0x7db4e348β¦ffc45e
- 498,487.66 OUSD was transferred back to the deployer of the OUSD contract (Origin Protocol)
https://etherscan.io/tx/0x2c9d2029β¦ba211f
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Origin Protocol, these are the critical security checks that could have prevented this incident (November 2020).
- Verify all logic paths related to Flashloan Reentrancy Attack / Flash Loan Attack are guarded by proper access controls and input validation - see the Flash Loans Attacks attack class for patterns
- Check that all state-changing functions follow the Checks-Effects-Interactions (CEI) pattern to prevent reentrancy and logic ordering bugs
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialRelated Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Sources & References
-
01
Source 1 https://rekt.news/hack-epidemic/
- 02
Learn to Prevent the Next Origin Protocol
The Origin Protocol hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.